Description
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1484 | libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution. |
Github GHSA |
GHSA-78h3-pg4x-j8cv | libxmljs2 vulnerable to type confusion when parsing specially crafted XML |
References
History
Mon, 25 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Marudor
Marudor libxmljs2 |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:2.3:a:marudor:libxmljs2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Marudor
Marudor libxmljs2 |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2024-11-25T12:54:08.634Z
Reserved: 2024-05-02T11:56:38.361Z
Link: CVE-2024-34394
Updated: 2024-08-02T02:51:11.412Z
Status : Awaiting Analysis
Published: 2024-05-02T19:15:06.630
Modified: 2024-11-25T13:15:06.407
Link: CVE-2024-34394
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA