Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-25062

Published: February 5, 2024Last modified: November 5, 2024

Description

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Fixed (2.10.4-r1)
Streamlibxml2Fixed (2.12.5-r0)
Liberica JDK8jdk-fullFixed (8u432+7)
jre-fullFixed (8u432+7)
11jdk-fullFixed (11.0.25+11)
jre-fullFixed (11.0.25+11)
17jdk-fullFixed (17.0.13+12)
jre-fullFixed (17.0.13+12)
21jdk-fullFixed (21.0.5+11)
jre-fullFixed (21.0.5+11)
23jdk-fullFixed (23.0.1+13)
jre-fullFixed (23.0.1+13)
Liberica NIK23 (JDK 17)fullFixed (23.0.6+1)
23 (JDK 21)fullFixed (23.1.5+1)
24 (JDK 23)fullFixed (24.1.1+1)

References

Published BELL-SAs

ON THIS PAGE