Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.
References
Link Resource
https://gitlab.gnome.org/GNOME/libxml2/-/issues/535 Exploit Issue Tracking Patch
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-08-29T00:00:00

Updated: 2023-09-06T16:22:09.464564

Reserved: 2023-08-07T00:00:00


Link: CVE-2023-39615

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-08-29T17:15:12.527

Modified: 2024-05-17T02:27:03.623


Link: CVE-2023-39615

JSON object: View

cve-icon Redhat Information

No data.

CWE