Описание
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.15.2+dfsg-0.1 |
| esm-infra-legacy/trusty | not-affected | 2.9.1+dfsg1-3ubuntu4.13+esm11 |
| esm-infra-legacy/xenial | not-affected | 2.9.3+dfsg1-1ubuntu0.7+esm12 |
| esm-infra/bionic | not-affected | 2.9.4+dfsg1-6.1ubuntu1.9+esm7 |
| esm-infra/focal | not-affected | 2.9.10+dfsg-5ubuntu0.20.04.10+esm4 |
| esm-infra/xenial | not-affected | 2.9.3+dfsg1-1ubuntu0.7+esm12 |
| jammy | released | 2.9.13+dfsg-1ubuntu0.12 |
| noble | released | 2.9.14+dfsg-1.3ubuntu3.8 |
| questing | not-affected | 2.14.5+dfsg-0.2ubuntu0.1 |
| resolute | not-affected | 2.15.2+dfsg-0.1 |
Показывать по
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 ...
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
EPSS
9.8 Critical
CVSS3