REDHAT-BUG-2360768: Medium severity Gnome libxml2 vulnerability
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2360768?
The severity of REDHAT-BUG-2360768 is considered critical due to the potential for exploitation through crafted XML documents.
How do I fix REDHAT-BUG-2360768?
To fix REDHAT-BUG-2360768, upgrade libxml2 to version 2.14.2 or later, or 2.13.8 as applicable.
What software is affected by REDHAT-BUG-2360768?
REDHAT-BUG-2360768 affects GNOME libxml2 versions before 2.13.8 and versions 2.14.0 through 2.14.2.
What type of vulnerability is REDHAT-BUG-2360768?
REDHAT-BUG-2360768 is a heap-based buffer under-read vulnerability that can lead to unauthorized access or crashes.
Can REDHAT-BUG-2360768 be exploited remotely?
Yes, REDHAT-BUG-2360768 can be exploited remotely if a crafted XML document is processed by the affected software.