cbcvebase.
CVE-2021-3517
published 2021-05-19

CVE-2021-3517: There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed…

high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-6.6 (bookworm)libxml2 2.9.10+dfsg-6.6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccm1_libxml2_2.9.12-1_on_cbl_mariner_1.0
netappe-series_santricity_os_controller11.0.0 – 11.70.1
nokogirinokogiri>= 0 < 1.11.41.11.4
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclemysql_workbench<= 8.0.26
oracleopenjdk
oraclepeoplesoft_enterprise_peopletools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
oraclezfs_storage_appliance_kit
redhatenterprise_linux
xmlsoftlibxml2< 2.9.112.9.11
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-5ubuntu0.20.04.12.9.10+dfsg-5ubuntu0.20.04.1

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
ghsa7.5HIGH
osv9.1CRITICAL