Use-after-free in Libxml2 - CVE-2023-45322

 

Use-after-free in Libxml2 - CVE-2023-45322

Published: November 20, 2023


Vulnerability identifier: #VU83291
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-45322
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Libxml2
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
ObjectScale
Storage Resource Manager
Storage Ceph
SmartFabric OS10
libxml2
libxml2-2-32bit
libxml2-2-debuginfo-32bit
libxml2-doc
libxml2-2
libxml2-2-debuginfo
python-libxml2
libxml2-debugsource
libxml2-devel
python-libxml2-debuginfo
libxml2-tools
libxml2-tools-debuginfo
python-libxml2-debugsource
python3-libxml2-python
python-libxml2-python-debugsource
python3-libxml2-python-debuginfo
libxml2-help
python3-libxml2
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
python311-libxml2
python3-libxml2-debuginfo
python311-libxml2-debuginfo
libxml2-python-debugsource
libxml2-2-32bit-debuginfo
libxml2-devel-32bit
libxml2-devel-64bit
libxml2-2-64bit-debuginfo
libxml2-2-64bit
libxml2-static
dev-libs/libxml2
Dell EMC Storage Monitoring and Reporting (SMR)
NetWorker
Autodesk Infraworks

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the xmlUnlinkNode() function in tree.c. A remote attacker can pass a specially crafted input to the application and perform a denial of service (DoS) attack.



How to mitigate CVE-2023-45322

Install updates from vendor's website.

Sources