HIGH 7.5 Microsoft
CVE-2024-25062
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Microsoft Security Update 2024-Feb: An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Affected Products
- cbl2 libxml2 2.10.4-4 on CBL Mariner 2.0
- azl3 libxml2 2.11.5-4 on Azure Linux 3.0
- cbl2 libxml2 2.10.4-6 on CBL-Mariner 2.0
- cbl2 libxml2 2.10.4-6 on CBL Mariner 2.0
- azl3 libxml2 2.11.5-5 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-25062
- https://nvd.nist.gov/vuln/detail/CVE-2024-25062
This high severity vulnerability with a CVSS score of 7.5 was published on 2024-02-13 via Microsoft. Affected: cbl2 libxml2 2.10.4-4 on CBL Mariner 2.0, azl3 libxml2 2.11.5-4 on Azure Linux 3.0, cbl2 libxml2 2.10.4-6 on CBL-Mariner 2.0 and 2 more.
vulnfeed aggregates 11976 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.