First published: Sun Feb 04 2024(Updated: )
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xmlsoft Libxml2 | <2.11.7 | |
Xmlsoft Libxml2 | >=2.12.0<2.12.5 | |
redhat/libxml2 2.11.7 and libxml2 | <2.12.5 | 2.12.5 |
debian/libxml2 | <=2.9.10+dfsg-6.7+deb11u4<=2.9.10+dfsg-6.7+deb11u5<=2.9.14+dfsg-1.3~deb12u1<=2.9.14+dfsg-1.3 | 2.12.7+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.