Insecure functionality In libxml2
Description
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 2.12.7+dfsg+really2.9.14-1 | ||
alpine v3.18 | 2.11.7-r0 | ||
alpine v3.19 | 2.11.7-r0 | ||
alpine v3.20 | 2.12.5-r0 | ||
alpine v3.21 | 2.12.5-r0 | ||
alpine v3.22 | 2.12.5-r0 | ||
debian 12 | 2.9.14+dfsg-1.3~deb12u2 | ||
debian 13 | 2.12.7+dfsg+really2.9.14-1 | ||
alpine v3.23 | 2.12.5-r0 | ||
rpm rhel8.8 | 0:2.9.7-16.el8_8.4 |
1-10 of 17
10
Aliases
1. 2. 3. 4. 5. 6. 7.