Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v48g-p9p2-j8cr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

EPSS

Процентиль: 77%
0.01052
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

redhat
больше 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

nvd
почти 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

debian
почти 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allo ...

fstec
почти 10 лет назад

Уязвимость операционной системы Ubuntu, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01052
Низкий

Дефекты

CWE-119