First published: Sat May 01 2021(Updated: )
A NULL pointer dereference flaw was found in libxml2, where it did not propagate errors while parsing XML mixed content. This flaw causes the application to crash if an untrusted XML document is parsed in recovery mode and post validated. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-apr-util | <0:1.6.1-91.el8 | 0:1.6.1-91.el8 |
redhat/jbcs-httpd24-curl | <0:7.78.0-3.el8 | 0:7.78.0-3.el8 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-80.el8 | 0:2.4.37-80.el8 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-41.el8 | 0:1.39.2-41.el8 |
redhat/jbcs-httpd24-openssl | <1:1.1.1g-11.el8 | 1:1.1.1g-11.el8 |
redhat/jbcs-httpd24-openssl-chil | <0:1.0.0-11.el8 | 0:1.0.0-11.el8 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0:0.4.10-26.el8 | 0:0.4.10-26.el8 |
redhat/jbcs-httpd24-apr-util | <0:1.6.1-91.jbcs.el7 | 0:1.6.1-91.jbcs.el7 |
redhat/jbcs-httpd24-curl | <0:7.78.0-3.jbcs.el7 | 0:7.78.0-3.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-80.jbcs.el7 | 0:2.4.37-80.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-41.jbcs.el7 | 0:1.39.2-41.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1:1.1.1g-11.jbcs.el7 | 1:1.1.1g-11.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil | <0:1.0.0-11.jbcs.el7 | 0:1.0.0-11.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0:0.4.10-26.jbcs.el7 | 0:0.4.10-26.jbcs.el7 |
redhat/libxml2 | <0:2.9.7-9.el8_4.2 | 0:2.9.7-9.el8_4.2 |
redhat/libxml2 | <2.9.11 | 2.9.11 |
IBM Security Verify Access OIDC Provider | <=10.0.0 | |
libxml2-devel | <2.9.11 | |
Red Hat JBoss Core Services | ||
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Debian | =9.0 | |
Fedora | =33 | |
Fedora | =34 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
IBM Data ONTAP | ||
NetApp ONTAP Antivirus Connector | ||
NetApp Manageability SDK | ||
NetApp ONTAP Select Deploy | ||
NetApp SnapDrive for Windows | ||
NetApp H410C | ||
NetApp H410C | ||
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.10.0 | |
Oracle Enterprise Manager | =13.4.0.0 | |
Oracle Enterprise Manager | =13.5.0.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
Oracle MySQL Workbench CE | <=8.0.26 | |
OpenJDK 8 | =8-update301 | |
Oracle Peoplesoft Enterprise Campus Software Campus Community | =8.58 | |
Oracle Real User Experience Insight | =13.4.1.0 | |
Oracle Real User Experience Insight | =13.5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this flaw is CVE-2021-3537.
The severity of CVE-2021-3537 is high, with a severity value of 7.
CVE-2021-3537 affects libxml2 versions before 2.9.11 by causing a NULL pointer dereference while parsing XML mixed content.
An attacker can exploit CVE-2021-3537 by providing an untrusted XML document in recovery mode and post-validation, which can crash the application.
Yes, the fix for CVE-2021-3537 is to update to libxml2 version 2.9.11 or newer.