CVE-2025-32414

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
References
Link Resource
https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 Exploit Issue Tracking Patch
https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

23 Apr 2025, 19:09

Type Values Removed Values Added
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 - Exploit, Issue Tracking, Patch
CWE CWE-252
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Xmlsoft
Xmlsoft libxml2
CPE cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

08 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 03:15

Updated : 2025-04-23 19:09


NVD link : CVE-2025-32414

Mitre link : CVE-2025-32414


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-252

Unchecked Return Value