CVE-2022-29824
PoC ×2—CVSS 3.1
6.5 medium
EPSS
4%p89
Published
()
Modified
Description
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
- Vendors
- xmlsoftfedoraprojectdebiannetapporacle
- Products
- libxml2, libxslt, fedora, debian linux, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, manageability software development kit, ontap select deploy administration utility, smi-s provider, snapdrive, snapmanager
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.