Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3518

Опубликовано: 22 апр. 2021
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

There's a flaw in libxml2. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Отчет

This flaw is out of support scope for Red Hat Enterprise Linux 6 and 7. To learn more about Red Hat Enterprise Linux support life cycles, please see https://access.redhat.com/support/policy/updates/errata .

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 9libxml2Not affected
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_cluster-nativeFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2022:138920.04.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1954242libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c

EPSS

Процентиль: 41%
0.00188
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

CVSS3: 8.8
nvd
больше 4 лет назад

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

CVSS3: 8.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 8.8
debian
больше 4 лет назад

There's a flaw in libxml2 in versions before 2.9.11. An attacker who i ...

CVSS3: 8.8
github
около 3 лет назад

Nokogiri Implements libxml2 version vulnerable to use-after-free

EPSS

Процентиль: 41%
0.00188
Низкий

8.6 High

CVSS3