Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q4w-wqgx-423v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

Ссылки

EPSS

Процентиль: 48%
0.00246
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 9 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

redhat
около 10 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

nvd
больше 9 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

debian
больше 9 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allow ...

fstec
больше 9 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 48%
0.00246
Низкий

Дефекты

CWE-119