CVE-2023-39615

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-39615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-39615
Related
Withdrawn
2023-09-06T16:22:09Z
Published
2023-08-29T17:15:12Z
Modified
2024-09-18T03:25:02.586372Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.

References

Affected packages

Debian:11 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u1
2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u5
2.9.12+dfsg-1
2.9.12+dfsg-2
2.9.12+dfsg-3
2.9.12+dfsg-4
2.9.12+dfsg-5
2.9.12+dfsg-6
2.9.13+dfsg-1
2.9.14+dfsg-1
2.9.14+dfsg-1.1
2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3
2.12.3+dfsg-0exp1
2.12.5+dfsg-0exp1
2.12.6+dfsg-0exp1
2.12.6+dfsg-0exp2
2.12.7+dfsg-1
2.12.7+dfsg-2
2.12.7+dfsg-3
2.13.1+dfsg-0exp1
2.13.3+dfsg-0exp1
2.13.3+dfsg-0exp2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3
2.12.3+dfsg-0exp1
2.12.5+dfsg-0exp1
2.12.6+dfsg-0exp1
2.12.6+dfsg-0exp2
2.12.7+dfsg-1
2.12.7+dfsg-2
2.12.7+dfsg-3
2.13.1+dfsg-0exp1
2.13.3+dfsg-0exp1
2.13.3+dfsg-0exp2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3
2.12.3+dfsg-0exp1
2.12.5+dfsg-0exp1
2.12.6+dfsg-0exp1
2.12.6+dfsg-0exp2
2.12.7+dfsg-1
2.12.7+dfsg-2
2.12.7+dfsg-3
2.13.1+dfsg-0exp1
2.13.3+dfsg-0exp1
2.13.3+dfsg-0exp2

Ecosystem specific

{
    "urgency": "not yet assigned"
}