Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-34459

Опубликовано: 08 мая 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.

A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the --htmlout command line option, causing an application crash and resulting in a denial of service.

Отчет

This issue only affects the xmllint program when the `--htmlout' command line option is used. Additionally, an application is not vulnerable if it does not use or expose the xmllint program.

Меры по смягчению последствий

Do not process untrusted files with the xmllint program.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Fix deferred
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat JBoss Core Serviceslibxml2Affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2280532libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c

EPSS

Процентиль: 37%
0.00153
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.

CVSS3: 7.5
nvd
около 1 года назад

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
около 1 года назад

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2. ...

suse-cvrf
12 месяцев назад

Security update for libxml2

EPSS

Процентиль: 37%
0.00153
Низкий

5.5 Medium

CVSS3