CVE-2024-25062
libxml2: use-after-free in XMLReader
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Se descubrió un problema en libxml2 anterior a 2.11.7 y 2.12.x anterior a 2.12.5. Cuando se utiliza la interfaz del Lector XML con la validación DTD y la expansión XInclude habilitada, el procesamiento de documentos XML manipulados puede generar un use-after-free de xmlValidatePopElement.
A use-after-free flaw was found in libxml2. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-02-04 CVE Reserved
- 2024-02-04 CVE Published
- 2024-02-13 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/tags | Release Notes |
URL | Date | SRC |
---|---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-25062 | 2024-06-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2262726 | 2024-06-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xmlsoft Search vendor "Xmlsoft" | Libxml2 Search vendor "Xmlsoft" for product "Libxml2" | < 2.11.7 Search vendor "Xmlsoft" for product "Libxml2" and version " < 2.11.7" | - |
Affected
| ||||||
Xmlsoft Search vendor "Xmlsoft" | Libxml2 Search vendor "Xmlsoft" for product "Libxml2" | >= 2.12.0 < 2.12.5 Search vendor "Xmlsoft" for product "Libxml2" and version " >= 2.12.0 < 2.12.5" | - |
Affected
|