Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxj8-hpwc-88mp

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

Ссылки

EPSS

Процентиль: 77%
0.01069
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 16 лет назад

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

redhat
около 16 лет назад

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

nvd
около 16 лет назад

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

debian
около 16 лет назад

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6 ...

oracle-oval
около 16 лет назад

ELSA-2009-1206: libxml and libxml2 security update (MODERATE)

EPSS

Процентиль: 77%
0.01069
Низкий

Дефекты

CWE-119