Description
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2653-1 | libxml2 security update |
EUVD |
EUVD-2022-1938 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability. |
Github GHSA |
GHSA-286v-pcf5-25rc | Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing |
Ubuntu USN |
USN-4991-1 | libxml2 vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Clustered Data Ontap
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
Hci H410c
Subscribe
Hci H410c Firmware
Subscribe
Manageability Software Development Kit
Subscribe
Ontap Select Deploy Administration Utility
Subscribe
Snapdrive
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager Ops Center
Subscribe
Mysql Workbench
Subscribe
Openjdk
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Real User Experience Insight
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Rhmt
Subscribe
Xmlsoft
Subscribe
Libxml2
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:08.318Z
Reserved: 2021-05-05T00:00:00.000Z
Link: CVE-2021-3537
No data.
Status : Modified
Published: 2021-05-14T20:15:16.553
Modified: 2024-11-21T06:21:47.317
Link: CVE-2021-3537
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN