ZeroHour

CVE-2022-40303

CVSS 3.1
7.5 high
EPSS
23%p98
Published
()
Modified
Description

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

Vendors
xmlsoftnetappapple
Products
libxml2, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, netapp manageability sdk, ontap select deploy administration utility, snapmanager, ipados, iphone os, macos, tvos, watchos
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news