Описание
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libxml2 | fixed | 2.12.3+dfsg-0exp1 | experimental | package |
| libxml2 | fixed | 2.12.7+dfsg+really2.9.14-0.4 | package |
Примечания
Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/5a19e21605398cef6a8b1452477a8705cb41562b (v2.11.0)
https://github.com/php/php-src/issues/17467
Связанные уязвимости
CVSS3: 8.1
ubuntu
10 месяцев назад
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
CVSS3: 5.9
redhat
10 месяцев назад
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
CVSS3: 8.1
nvd
10 месяцев назад
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
CVSS3: 8.1
msrc
9 месяцев назад
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.