CVE-2023-28484: Null Pointer Dereference
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
Other sources
NULL pointer dereference when parsing (invalid) XML schemas.
References:
https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4 https://gitlab.gnome.org/GNOME/libxml2/-/commit/647e072ea0a2f12687fa05c172f4c4713fdb0c4f https://gitlab.gnome.org/GNOME/libxml2/-/commit/4c6922f763ad958c48ff66f82823ae21f2e92ee6
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.117.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.10.4 - Upgrade
Upgrade
GNOME libxml2to a version that resolves this vulnerability.Fixed in 2.10.4
Event History
Frequently Asked Questions
What is CVE-2023-28484?
CVE-2023-28484 is a vulnerability in libxml2 that can lead to a NULL pointer dereference and subsequently a segfault when parsing certain invalid XSD schemas.
How does CVE-2023-28484 affect libxml2?
CVE-2023-28484 affects libxml2 versions before 2.10.4.
What is the severity of CVE-2023-28484?
CVE-2023-28484 has a severity value of 6.5.
How can I fix CVE-2023-28484?
To fix CVE-2023-28484, update libxml2 to version 2.10.4 or later.
Where can I find more information about CVE-2023-28484?
You can find more information about CVE-2023-28484 at the following references: [link1], [link2], [link3].