PT-2024-40852 · Libxml2 · Libxml2

Published

2024-02-08

·

Updated

2024-02-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions libxml2 (affected versions not specified)
Description The issue is related to a heap-use-after-free error, which occurs when the program attempts to access memory that has already been freed. This error is specifically a READ 8 type, indicating an attempt to read 8 bytes from a freed memory location. The crash state involves several functions, including xmlValidatePopElement, xmlTextReaderValidatePop, and xmlTextReaderRead. These functions are part of the XML parsing process, suggesting that the issue may be triggered by malformed or specially crafted XML input.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

OSV-2024-82

Affected Products

Libxml2