Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-45322

Опубликовано: 23 авг. 2023
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.

Отчет

The libxml2 project does not consider this issue to be a vulnerability because it can only be triggered in an out-of-memory condition or when the --maxmem command line option of the xmllint program is used to limit the number of memory allocation done by the parser. This is intended behavior and it's used to detect similar issues. Red Hat Product Security agrees with that decision. However, Red Hat will try to address this issue in affected products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Fix deferred
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat JBoss Core Serviceslibxml2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2242945libxml2: use-after-free in xmlUnlinkNode() in tree.c

EPSS

Процентиль: 24%
0.00076
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

CVSS3: 6.5
nvd
больше 1 года назад

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

CVSS3: 6.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
больше 1 года назад

libxml2 through 2.11.5 has a use-after-free that can only occur after ...

suse-cvrf
больше 1 года назад

Security update for libxml2

EPSS

Процентиль: 24%
0.00076
Низкий

5.9 Medium

CVSS3