PT-2021-7860 · Ezxml+3 · Ezxml+3

Cve Reporting

·

Published

2021-01-24

·

Updated

2021-12-23

·

CVE-2021-26221

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions ezXML versions 0.8.6 and earlier
Description The issue is related to the ezxml new function in the ezXML library, which is vulnerable to an out-of-bounds (OOB) write when opening an XML file after exhausting the memory pool. This can allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations For ezXML versions 0.8.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03826
CVE-2021-26221
MGASA-2021-0580
OPENSUSE-SU-2021:1505-1
OPENSUSE-SU-2021:3804-1
OPENSUSE-SU-2021:3805-1
OPENSUSE-SU-2021:3815-1
OPENSUSE-SU-2021:3873-1
OPENSUSE-SU-2021_1505-1
OPENSUSE-SU-2021_3804-1
OPENSUSE-SU-2021_3805-1
OPENSUSE-SU-2021_3815-1
OPENSUSE-SU-2021_3873-1
SUSE-SU-2021:3804-1
SUSE-SU-2021:3805-1
SUSE-SU-2021:3815-1
SUSE-SU-2021:3873-1

Affected Products

Astra Linux
Debian
Suse
Ezxml