Back to search
CVE-2022-29824
Published: May 3, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2022-9136d646e4
vendor-advisory
FEDORA-2022-be6d83642a
vendor-advisory
FEDORA-2022-f624aad735
vendor-advisory
DSA-5142
vendor-advisory
GLSA-202210-03
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now