Описание
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
A flaw was found in libxml2. When a reference cycle is detected in the XML entity cleanup function the XML entity data can be stored in a dictionary. In this case, the dictionary becomes corrupted resulting in logic errors, including memory errors like double free.
Отчет
The most likely impact of this flaw is a Denial of Service in the application linked to the library. To reflect this, Red Hat Product Security has rated this flaw as having a moderate security impact.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | libxml2 | Out of support scope | ||
Red Hat Enterprise Linux 7 | libxml2 | Out of support scope | ||
Red Hat Enterprise Linux 8 | libxml2 | Fixed | RHSA-2023:0173 | 16.01.2023 |
Red Hat Enterprise Linux 8 | libxml2 | Fixed | RHSA-2023:0173 | 16.01.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | libxml2 | Fixed | RHSA-2024:0413 | 25.01.2024 |
Red Hat Enterprise Linux 9 | libxml2 | Fixed | RHSA-2023:0338 | 23.01.2023 |
Red Hat Enterprise Linux 9 | libxml2 | Fixed | RHSA-2023:0338 | 23.01.2023 |
Text-Only JBCS | libxml2 | Fixed | RHSA-2022:8841 | 08.12.2022 |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML ...
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
Уязвимость функции очистки объекта XML библиотеки анализа XML-документов libxml2, позволяющая нарушителю вызвать отказ в обслуживании
7.8 High
CVSS3