Out-of-bounds write in Libxml2 - CVE-2021-3517

 

Out-of-bounds write in Libxml2 - CVE-2021-3517

Published: June 18, 2021


Vulnerability identifier: #VU54224
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3517
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in the xml entity encoding functionality. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

Libxml2
HPE B-series SN6750B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
IBM Flex System CN4093 10Gb Converged Scalable Switch
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE MicroOS
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
openEuler
Fedora
Brocade Fabric OS
cflinuxfs3
APM Edge
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
Solutions Enabler
Unisphere 360
Unisphere for PowerMax
Unisphere for PowerMax Virtual Appliance
VASA Provider Standalone
Dell Command | Update
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
mediawiki (Debian package)
libxml2-debuginfo
libxml2-python
libxml2-doc
libxml2
libxml2-32bit
libxml2-python-debugsource
libxml2-python-debuginfo
libxml2-debugsource
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
python-libxml2-debuginfo
libxml2-devel
libxml2-2
libxml2-2-debuginfo
libxml2-tools
libxml2-tools-debuginfo
python-libxml2
python-libxml2-debugsource
libxml2-2-32bit
libxml2-2-debuginfo-32bit
libxml2-2-32bit-debuginfo
python-libxml2-python-debugsource
python2-libxml2-python
python2-libxml2-python-debuginfo
python3-libxml2-python
python3-libxml2-python-debuginfo
libxml2 (Red Hat package)
python3-libxml2
python2-libxml2
libxml2-help
qt5-qtwebengine
Service Telemetry Framework
Dell EMC Data Protection Search
EMC Data Protection Advisor
Migration Toolkit for Containers
Oracle ZFS Storage Appliance Kit
Cloud Pak for Security (CP4S)
EMC ESRS Policy Manager
Red Hat OpenShift Jaeger
EMC Integrated Data Protection Appliance
JBoss Core Services
SecureTransport
Oracle Java SE
IBM Security Verify Access
RTU500 CMU
Web Terminal
OpenShift Virtualization
Solutions Enabler Virtual Appliance
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
SecurID Authentication Manager

How to mitigate CVE-2021-3517

Install updates from vendor's website.

Libxml2 - update to 2.9.11
cflinuxfs3 - update to 0.245.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-26.el8jbcs, 0.4.10-26.jbcs.el7
APM Edge - update to 4.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-11.el8jbcs, 1.0.0-11.jbcs.el7
Migration Toolkit for Containers - addressed in versions 1.4.6, 1.5.1
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-91.el8jbcs, 1.6.1-91.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-22.el8jbcs, 1.15.7-22.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.20.5, 1.24.0
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-41.el8jbcs, 1.39.2-41.jbcs.el7
EMC Integrated Data Protection Appliance - update to 2.7.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-41.el8jbcs, 2.0.8-41.jbcs.el7
JBoss Core Services - update to 2.4.37 SP11
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-80.el8jbcs, 2.4.37-80.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-68.GA.el8jbcs, 2.9.2-68.GA.jbcs.el7
SecureTransport - update to 5.5-20220127
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-3.el8jbcs, 7.78.0-3.jbcs.el7
RTU500 CMU - addressed in versions 12.0.14.0, 12.2.11.0, 12.4.11, 12.6.7, 12.7.2, 13.2.3
Dell EMC Data Protection Search - update to 19.6.0
Web Terminal - update to 1.3
mediawiki (Debian package) - addressed in versions 1:1.35.13-1~deb11u1, 1:1.39.5-1~deb12u1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0, 4.8.1
libxml2-debuginfo - update to 2.7.6-0.77.36.1
libxml2-python - update to 2.7.6-0.77.36.1
libxml2-doc - addressed in versions 2.7.6-0.77.36.1, 2.9.4-46.40.1, 2.9.4-46.43.1
libxml2 - update to 2.7.6-0.77.36.1
libxml2-32bit - update to 2.7.6-0.77.36.1
libxml2-python-debugsource - update to 2.7.6-0.77.36.1
libxml2-python-debuginfo - update to 2.7.6-0.77.36.1
libxml2-debugsource - addressed in versions 2.7.6-0.77.36.1, 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2 - update to 2.9.1-6.6.42
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.4, 2.9.10+dfsg-6.3ubuntu0.1, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.10.2
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.4, 2.9.10+dfsg-6.3ubuntu0.1, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.10.2
python-libxml2-debuginfo - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1
libxml2-devel - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2-2 - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2-tools - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
python-libxml2 - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1
python-libxml2-debugsource - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1
libxml2-2-32bit - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1, 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2-2-debuginfo-32bit - addressed in versions 2.9.4-46.40.1, 2.9.4-46.43.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
python-libxml2-python-debugsource - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
python2-libxml2-python - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
python2-libxml2-python-debuginfo - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
python3-libxml2-python - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
python3-libxml2-python-debuginfo - addressed in versions 2.9.7-3.31.1, 2.9.7-3.34.1
libxml2 (Red Hat package) - update to 2.9.7-9.el8_4.2
libxml2-devel - update to 2.9.7-9.0.1
python3-libxml2 - update to 2.9.7-9.0.1
libxml2 - update to 2.9.7-9.0.1
libxml2 - addressed in versions 2.9.10-12.fc34, 2.9.12-4.fc33
libxml2 - update to 2.9.10-16
libxml2-devel - update to 2.9.10-16
python2-libxml2 - update to 2.9.10-16
python3-libxml2 - update to 2.9.10-16
libxml2-help - update to 2.9.10-16
libxml2-debuginfo - update to 2.9.10-16
libxml2-debugsource - update to 2.9.10-16
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ESRS Policy Manager - update to 5.10.00.00
qt5-qtwebengine - addressed in versions 5.15.8-2.fc34, 5.15.8-2.fc35
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.31.0
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.31.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.31.0
IBM Flex System CN4093 10Gb Converged Scalable Switch - update to 7.8.31.0
SecurID Authentication Manager - update to 8.5 Patch 5
Solutions Enabler - addressed in versions 9.1.0.18, 9.2.3.0
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.18, 9.2.3.0
Unisphere 360 - addressed in versions 9.1.0.29, 9.2.3.3
Unisphere for PowerMax - addressed in versions 9.1.0.31, 9.2.3.4
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.31, 9.2.3.4
VASA Provider Standalone - addressed in versions 9.1.0.723, 9.2.3.0
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
Dell Command | Update - update to 10.5.1.114
EMC Data Protection Advisor - addressed in versions 19.4 B108, 19.5 B83, 19.6 B33

External References

Related Security Bulletins