Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23308

Опубликовано: 20 фев. 2022
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

A flaw was found in libxml2. A call to the xmlGetID function can return a pointer already freed when parsing an XML document with the XML_PARSE_DTDVALID option and without the XML_PARSE_NOENT option, resulting in a use-after-free issue.

Отчет

The security impact of xmlGetID() returning a pointer to freed memory depends on the application and will mostly result in a denial of service (DoS). The typical use case of calling xmlGetID() on an unmodified document is not affected, therefore this issue was rated with a moderate severity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 9libxml2Not affected
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_cluster-nativeFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2022:138920.04.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2056913libxml2: Use-after-free of ID and IDREF attributes

EPSS

Процентиль: 13%
0.00045
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVSS3: 7.5
nvd
больше 3 лет назад

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF ...

suse-cvrf
больше 3 лет назад

Security update for python-libxml2-python

EPSS

Процентиль: 13%
0.00045
Низкий

8.1 High

CVSS3