PT-2021-7862 · Ezxml+4 · Ezxml+4
Rc0R
·
Published
2021-04-01
·
Updated
2022-05-16
·
CVE-2021-30485
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ezXML version 0.8.6
Description
An issue in the ezXML library for parsing XML documents is related to pointer dereference errors. The function
ezxml internal dtd() performs incorrect memory handling while parsing a crafted XML file, leading to a NULL pointer dereference. This can be exploited by a remote attacker to cause a denial of service using a specially crafted XML file.Recommendations
For ezXML version 0.8.6, as a temporary workaround, consider disabling the
ezxml internal dtd() function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Suse
Ubuntu
Ezxml