PT-2021-7861 · Ezxml+3 · Ezxml+3

Published

2021-01-23

·

Updated

2021-12-23

·

CVE-2021-26222

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions ezXML versions 0.8.6 and earlier
Description The issue is related to the ezxml new function in ezXML, which is vulnerable to an out-of-bounds (OOB) write when opening an XML file after exhausting the memory pool. This can allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations For ezXML versions 0.8.6 and earlier, consider disabling the ezxml new function until a patch is available to prevent potential exploitation. Restrict access to XML files to minimize the risk of OOB write attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03827
CVE-2021-26222
MGASA-2021-0580
OPENSUSE-SU-2021:1505-1
OPENSUSE-SU-2021:3804-1
OPENSUSE-SU-2021:3805-1
OPENSUSE-SU-2021:3815-1
OPENSUSE-SU-2021:3873-1
OPENSUSE-SU-2021_1505-1
OPENSUSE-SU-2021_3804-1
OPENSUSE-SU-2021_3805-1
OPENSUSE-SU-2021_3815-1
OPENSUSE-SU-2021_3873-1
SUSE-SU-2021:3804-1
SUSE-SU-2021:3805-1
SUSE-SU-2021:3815-1
SUSE-SU-2021:3873-1

Affected Products

Astra Linux
Debian
Suse
Ezxml