There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2653-1 | libxml2 security update |
EUVD |
EUVD-2022-4443 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application. |
Github GHSA |
GHSA-jw9f-hh49-cvp9 | Nokogiri contains libxml Out-of-bounds Write vulnerability |
Ubuntu USN |
USN-4991-1 | libxml2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T16:53:17.731Z
Reserved: 2021-04-27T00:00:00
Link: CVE-2021-3517
No data.
Status : Modified
Published: 2021-05-19T14:15:07.553
Modified: 2024-11-21T06:21:44.107
Link: CVE-2021-3517
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN