Описание
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
A flaw was found in libxml2. An integer overflow vulnerability exists in the xmlURIEscapeStr function within uri.c. This flaw could potentially lead to memory corruption, allowing an attacker to achieve information disclosure or arbitrary code execution.
Отчет
An issue within the libxml2 xmlURIEscapeStr function could lead to arbitrary code execution. Despite the severe potential impact, the overall vulnerability is rated Moderate due to its high attack complexity and the strict prerequisite of local system access, which collectively constrain its exploitability in standard Red Hat environments.
Меры по смягчению последствий
To mitigate this developers must strictly cap URI and path lengths before passing data to libxml2 helpers to ensure multi-gigabyte strings cannot reach the vulnerable function. Furthermore, administrators should enforce strict process or cgroup memory limits to structurally prevent applications from allocating the excessively large buffers required to exceed maximum integer boundaries during string processing.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 10 | podman | Not affected | ||
| Red Hat Enterprise Linux 6 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 7 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Not affected | ||
| Red Hat Enterprise Linux 8 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 9 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 9 | podman | Not affected | ||
| Red Hat Hardened Images | swift-lang | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected |
Показывать по
Дополнительная информация
Статус:
6.9 Medium
CVSS3
Связанные уязвимости
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer over ...
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
6.9 Medium
CVSS3