Heap-based buffer overflow in Libxml2 - CVE-2024-34459
Published: May 14, 2024
Vulnerability identifier: #VU89430
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-34459
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Affected software:
Libxml2
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Slackware Linux
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
Fedora
Voice Gateway
Nokogiri
IBM MQ Operator
Dell Secure Connect Gateway
Nessus Network Monitor
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2-2-debuginfo
libxml2-debugsource
libxml2-devel
libxml2-2
python-libxml2-debugsource
libxml2-tools
python-libxml2-debuginfo
python-libxml2
libxml2-tools-debuginfo
libxml2-doc
libxml2-2-debuginfo-32bit
libxml2-2-32bit
libxml2 (Red Hat package)
libxml2
python3-libxml2
python3-libxml2-python-debuginfo
python-libxml2-python-debugsource
python3-libxml2-python
libxml2-help
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
libxml2-2-64bit-debuginfo
python311-libxml2
libxml2-python-debugsource
python3-libxml2-debuginfo
libxml2-devel-64bit
libxml2-2-64bit
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
python311-libxml2-debuginfo
libxml2-static
mingw-libxml2
qt6-qtwebengine
IBM supplied MQ Advanced container images
webMethods Managed File Transfer
IBM CICS TX Advanced
Libxml2
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Slackware Linux
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
Fedora
Voice Gateway
Nokogiri
IBM MQ Operator
Dell Secure Connect Gateway
Nessus Network Monitor
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2-2-debuginfo
libxml2-debugsource
libxml2-devel
libxml2-2
python-libxml2-debugsource
libxml2-tools
python-libxml2-debuginfo
python-libxml2
libxml2-tools-debuginfo
libxml2-doc
libxml2-2-debuginfo-32bit
libxml2-2-32bit
libxml2 (Red Hat package)
libxml2
python3-libxml2
python3-libxml2-python-debuginfo
python-libxml2-python-debugsource
python3-libxml2-python
libxml2-help
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
libxml2-2-64bit-debuginfo
python311-libxml2
libxml2-python-debugsource
python3-libxml2-debuginfo
libxml2-devel-64bit
libxml2-2-64bit
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
python311-libxml2-debuginfo
libxml2-static
mingw-libxml2
qt6-qtwebengine
IBM supplied MQ Advanced container images
webMethods Managed File Transfer
IBM CICS TX Advanced
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when parsing XML data. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
How to mitigate CVE-2024-34459
Install updates from vendor's website.