PT-2017-4233 · Xmlsoft+2 · Libxml2+2
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 version 2.9.4
Description
The issue is related to a denial of service caused by a NULL pointer dereference when libxml2 is used in recover mode. This can be triggered by a remote attacker via a crafted XML document. The maintainer of libxml2 has stated that the Recover parsing option should only be used for manual recovery, at least for the XML parser.
Recommendations
For libxml2 version 2.9.4, consider disabling the recover mode to prevent exploitation until a patch is available. As a temporary workaround, avoid using the recover parsing option for automatic processing of XML documents.
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Libxml2