Impact
The vulnerability is a heap‑based buffer overflow in libxml2 prior to version 2.15.4, triggered by the xmlXPtrEvalXPtrPart function when evaluating xpointer expressions that exceed internal length limits. This flaw is identified as CWE‑122 and CWE‑805, and its exploitation could allow an attacker to corrupt heap memory, potentially leading to arbitrary code execution or a system crash.
Affected Systems
The vendor is xmlsoft and the product is libxml2; all releases older than 2.15.4 are affected. Systems that link with these older library versions and process XML input are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. The EPSS score of < 1% suggests a low exploitation probability. The vulnerability is listed in the vendor’s advisory and a patch is available. The attack vector is likely remote or local, depending on whether attackers can supply XML input to the affected process. Without mitigation, the flaw could be abused to hijack a process or crash a service.
OpenCVE Enrichment