CVE-2021-26220

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-26220
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26220.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-26220
Related
Published
2021-02-08T21:15:13Z
Modified
2025-01-14T09:01:26.638987Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

References

Affected packages

Debian:11 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.0-2
1.12.0~rc1-1~exp1
1.12.0-1~bpo11+1
1.12.0-1
1.12.1-1~bpo11+1
1.12.1-1
1.14.0-1~bpo11+1
1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4
1.14.1-1~bpo12+1
1.14.1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4
1.14.1-1~bpo12+1
1.14.1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4
1.14.1-1~bpo12+1
1.14.1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / netcdf

Package

Name
netcdf
Purl
pkg:deb/debian/netcdf?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*

1:4.7.4-1
1:4.8.0-1~exp1
1:4.8.1-1~exp1
1:4.8.1-1
1:4.9.0-1
1:4.9.0-2
1:4.9.0-3
1:4.9.1~rc1-1~exp1
1:4.9.1~rc2-1~exp1
1:4.9.1-1~exp1
1:4.9.2-1~exp1
1:4.9.2-1
1:4.9.2-2
1:4.9.2-3
1:4.9.2-3.1~exp1
1:4.9.2-4~exp1
1:4.9.2-4
1:4.9.2-5
1:4.9.2-6
1:4.9.2-7
1:4.9.3~rc1-1~exp1
1:4.9.3~rc2-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / netcdf

Package

Name
netcdf
Purl
pkg:deb/debian/netcdf?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:4.9.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / netcdf

Package

Name
netcdf
Purl
pkg:deb/debian/netcdf?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:4.9.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / netcdf-parallel

Package

Name
netcdf-parallel
Purl
pkg:deb/debian/netcdf-parallel?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*

1:4.7.4-1
1:4.8.1-1
1:4.8.1-2
1:4.9.0-1
1:4.9.0-3
1:4.9.0-4
1:4.9.0-5
1:4.9.0-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / netcdf-parallel

Package

Name
netcdf-parallel
Purl
pkg:deb/debian/netcdf-parallel?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:4.9.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / netcdf-parallel

Package

Name
netcdf-parallel
Purl
pkg:deb/debian/netcdf-parallel?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:4.9.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.0+dfsg1-7
6.1.1+dfsg2-1
6.1.1+dfsg2-2
6.1.1+dfsg2-3
6.1.1+dfsg2-4
6.1.1+dfsg2-4+0.riscv64.1
6.1.1+dfsg2-5
6.1.1+dfsg2-6~exp0
6.1.1+dfsg2-6~exp1
6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6
2024.1.0+dfsg-1
2024.1.0+dfsg-2
2024.1.0+dfsg-3
2024.1.0+dfsg-4
2024.1.0+dfsg-5
2024.1.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6
2024.1.0+dfsg-1
2024.1.0+dfsg-2
2024.1.0+dfsg-3
2024.1.0+dfsg-4
2024.1.0+dfsg-5
2024.1.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6
2024.1.0+dfsg-1
2024.1.0+dfsg-2
2024.1.0+dfsg-3
2024.1.0+dfsg-4
2024.1.0+dfsg-5
2024.1.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}