Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-45322

Published: October 6, 2023Last modified: January 24, 2024

Description

** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Notes

We agree with the libxml2 project decision that this issue should not be treated as a vulnerability, so the fix will not be ported to LTS releases.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Will not fix (2.10.3-r2)
Streamlibxml2Fixed (2.12.3-r0)

References

ON THIS PAGE