An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
References
Link | Resource |
---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 | Exploit Issue Tracking |
https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 | Exploit Issue Tracking |
https://gitlab.gnome.org/GNOME/libxml2/-/tags | Release Notes |
https://gitlab.gnome.org/GNOME/libxml2/-/tags | Release Notes |
Configurations
Configuration 1 (hide)
|
History
13 Feb 2024, 00:40
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
CWE | CWE-416 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Xmlsoft libxml2
Xmlsoft |
|
References | () https://gitlab.gnome.org/GNOME/libxml2/-/tags - Release Notes | |
References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 - Exploit, Issue Tracking |
04 Feb 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-04 16:15
Updated : 2025-05-09 18:16
NVD link : CVE-2024-25062
Mitre link : CVE-2024-25062
JSON object : View
Products Affected
xmlsoft
- libxml2
CWE
CWE-416
Use After Free