Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28484

Опубликовано: 11 апр. 2023
Источник: redhat
CVSS3: 5.9

Описание

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

A NULL pointer dereference vulnerability was found in libxml2. This issue occurs when parsing (invalid) XML schemas.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5rubygem-nokogiriNot affected
Red Hat 3scale API Management Platform 2nokogiriNot affected
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Satellite 6tfm-rubygem-nokogiriNot affected
Red Hat Enterprise Linux 8libxml2FixedRHSA-2023:452908.08.2023
Red Hat Enterprise Linux 8libxml2FixedRHSA-2023:452908.08.2023
Red Hat Enterprise Linux 8.6 Extended Update Supportlibxml2FixedRHSA-2024:041325.01.2024
Red Hat Enterprise Linux 9libxml2FixedRHSA-2023:434901.08.2023
Red Hat Enterprise Linux 9libxml2FixedRHSA-2023:434901.08.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2185994libxml2: NULL dereference in xmlSchemaFixupComplexType

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

CVSS3: 6.5
nvd
около 2 лет назад

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

CVSS3: 6.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 6.5
debian
около 2 лет назад

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can l ...

CVSS3: 6.5
github
около 2 лет назад

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

5.9 Medium

CVSS3