The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Jan 12, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Jan 11, 2008 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Oct 16, 2024 | Jan 12, 2008 |
| Suse | — | Upgrade libxml2Upgrade libxml2-toolsUpgrade libxml2-2Upgrade python313-libxml2Upgrade libxml2-devel-32bitUpgrade libxml2-32bitUpgrade libxml2-docUpgrade libxml2-x86Upgrade libxml2-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Jan 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub