Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40896

Опубликовано: 23 дек. 2024
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

A flaw was found in libxml2. In the affected versions of libxml2, the SAX parser can generate events for external entities, even if custom SAX handlers try to override entity content by setting it to "checked." This vulnerability allows classic  XML External Entity (XXE) attacks.

Отчет

This vulnerability is marked as critical severity instead of important due to its potential to completely compromise system security. By exploiting the XXE vulnerability, an attacker can achieve arbitrary file disclosure (e.g., reading /etc/passwd), which exposes sensitive system information and credentials. In worst-case scenarios, the flaw can lead to Remote Code Execution (RCE) in misconfigured environments or cause a Denial of Service (DoS) through resource exhaustion. The issue is especially critical because it stems from a broken protection mechanism (due to the renaming of the "checked" member), silently leaving downstream applications vulnerable without their knowledge.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mysql8.4Not affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat Enterprise Linux 6mysqlNot affected
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat Enterprise Linux 8libxml2Not affected
Red Hat Enterprise Linux 8mysql:8.0/mysqlWill not fix
Red Hat Enterprise Linux 9libxml2Not affected
Red Hat Enterprise Linux 9mysqlWill not fix
Red Hat Enterprise Linux 9mysql:8.4/mysqlNot affected
Red Hat JBoss Core Serviceslibxml2Not affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
nvd
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 9.1
debian
8 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.1 ...

suse-cvrf
6 месяцев назад

Security update for qt6-webengine

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3