https://seclists.org/oss-sec/2024/q4/181: CVE-2024-40896 Analysis: libxml2 XXE due to type confusion
Published Dec 26, 2024
·Updated
Affected Software
4 affected components
Redland Raptor<2.0.7
The Document Foundation LibreOffice<3.4.6, >3.5.1
The Apache Software Foundation OpenOffice<3.3, >3.4
Xmlsoft Libxml2
Frequently Asked Questions
1
What is the severity of CVE-2024-40896?
CVE-2024-40896 has been classified as a high severity vulnerability.
2
How do I fix CVE-2024-40896?
To fix CVE-2024-40896, you should upgrade to the latest version of libxml2 that addresses the XXE vulnerability.
3
Which software is affected by CVE-2024-40896?
CVE-2024-40896 affects libxml2 and may impact applications that utilize this library, including Redland Raptor and LibreOffice.
4
What kind of vulnerability is CVE-2024-40896?
CVE-2024-40896 is an XML External Entity (XXE) vulnerability resulting from type confusion.
5
When was CVE-2024-40896 published?
CVE-2024-40896 was published on December 26, 2024.