CVE-2022-29824
published 2022-05-03CVE-2022-29824: In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.63%
88.3th percentile
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.14+dfsg-1 (bookworm) | libxml2 2.9.14+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| msrc | cbl2_libxml2_2.9.14-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libxslt_1.1.34-7_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libxml2_2.9.14-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_libxslt_1.1.34-3_on_cbl_mariner_1.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.13.5 | 1.13.5 |
| oracle | zfs_storage_appliance_kit | — | — |
| xmlsoft | libxml2 | < 2.9.14 | 2.9.14 |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-6.7+deb11u2 | 2.9.10+dfsg-6.7+deb11u2 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1 | 2.9.14+dfsg-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1 | 2.9.14+dfsg-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1 | 2.9.14+dfsg-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-6.1ubuntu1.6 | 2.9.4+dfsg1-6.1ubuntu1.6 |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-5ubuntu0.20.04.3 | 2.9.10+dfsg-5ubuntu0.20.04.3 |
| xmlsoft | libxml2 | >= 0 < 2.9.13+dfsg-1ubuntu0.1 | 2.9.13+dfsg-1ubuntu0.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm3 | 2.9.1+dfsg1-3ubuntu4.13+esm3 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm2 | 2.9.3+dfsg1-1ubuntu0.7+esm2 |
| xmlsoft | libxslt | <= 1.1.35 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa6.5MEDIUM
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle HTTP Server 12.2.1.4.0 SSL Module denial of service (EUVD-2022-34142 / Nessus ID 224695)
vuldb·2026-05-23·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle HTTP Server 12.2.1.4.0 SSL Module denial of service (EUVD-2022-34142 / Nessus ID 224695)
A vulnerability has been found in Oracle HTTP Server 12.2.1.4.0 and classified as critical. This issue affects some unknown processing of the component SSL Module. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2022-29824. It is possible to initiate the attack remotely. There is no exploit available.
VulDB
Oracle Communications Cloud Native Core Network Function Cloud Native Environment Configuration denial of service (EUVD-2022-34142 / Nessus ID 224695)
vuldb·2026-05-23·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle Communications Cloud Native Core Network Function Cloud Native Environment Configuration denial of service (EUVD-2022-34142 / Nessus ID 224695)
A vulnerability was found in Oracle Communications Cloud Native Core Network Function Cloud Native Environment 22.2.1/22.2.0. It has been declared as critical. This impacts an unknown function of the component Configuration. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2022-29824. The attack can be launched remotely. No exploit exists.
VulDB
Oracle Communications Cloud Native Core Binding Support Function Install/Upgrade denial of service (EUVD-2022-34142 / Nessus ID 224695)
vuldb·2026-05-23·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle Communications Cloud Native Core Binding Support Function Install/Upgrade denial of service (EUVD-2022-34142 / Nessus ID 224695)
A vulnerability was found in Oracle Communications Cloud Native Core Binding Support Function 22.2.0. It has been classified as critical. The impacted element is an unknown function of the component Install/Upgrade. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2022-29824. The attack may be initiated remotely. There is no available exploit.
VulDB
libxml2 up to 2.9.13 buf.c integer overflow (EUVD-2022-34142 / Nessus ID 224695)
vuldb·2026-05-23·CVSS 6.5
CVE-2022-29824 [MEDIUM] libxml2 up to 2.9.13 buf.c integer overflow (EUVD-2022-34142 / Nessus ID 224695)
A vulnerability classified as critical has been found in libxml2 up to 2.9.13. This vulnerability affects unknown code of the file buf.c. This manipulation causes integer overflow.
This vulnerability appears as CVE-2022-29824. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
VulDB
Oracle MySQL Workbench up to 8.0.30 denial of service (EUVD-2022-34142 / Nessus ID 224695)
vuldb·2026-05-23·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle MySQL Workbench up to 8.0.30 denial of service (EUVD-2022-34142 / Nessus ID 224695)
A vulnerability categorized as critical has been discovered in Oracle MySQL Workbench up to 8.0.30. Affected by this vulnerability is an unknown functionality of the component Workbench. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2022-29824. The attack may be performed from remote. There is no available exploit.
GHSA
Integer Overflow or Wraparound in libxml2 affects Nokogiri
ghsa·2022-05-18·CVSS 6.5
CVE-2022-29824 [MEDIUM] CWE-190 Integer Overflow or Wraparound in libxml2 affects Nokogiri
Integer Overflow or Wraparound in libxml2 affects Nokogiri
### Summary
Nokogiri v1.13.5 upgrades the packaged version of its dependency libxml2 from v2.9.13 to [v2.9.14](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.9.14).
libxml2 v2.9.14 addresses [CVE-2022-29824](https://nvd.nist.gov/vuln/detail/CVE-2022-29824). This version also includes several security-related bug fixes for which CVEs were not created, including a potential double-free, potential memory leaks, and integer-overflow.
Please note that this advisory only applies to the CRuby implementation of Nokogiri `= 1.13.5`.
Users who are unable to upgrade Nokogiri may also choose a more complicated mitigation: compile and link Nokogiri against external libraries libxml2 `>= 2.9.14` which will also address these same issu
OSV
Integer Overflow or Wraparound in libxml2 affects Nokogiri
osv·2022-05-18·CVSS 6.5
CVE-2022-29824 [MEDIUM] Integer Overflow or Wraparound in libxml2 affects Nokogiri
Integer Overflow or Wraparound in libxml2 affects Nokogiri
### Summary
Nokogiri v1.13.5 upgrades the packaged version of its dependency libxml2 from v2.9.13 to [v2.9.14](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.9.14).
libxml2 v2.9.14 addresses [CVE-2022-29824](https://nvd.nist.gov/vuln/detail/CVE-2022-29824). This version also includes several security-related bug fixes for which CVEs were not created, including a potential double-free, potential memory leaks, and integer-overflow.
Please note that this advisory only applies to the CRuby implementation of Nokogiri `= 1.13.5`.
Users who are unable to upgrade Nokogiri may also choose a more complicated mitigation: compile and link Nokogiri against external libraries libxml2 `>= 2.9.14` which will also address these same issu
OSV
libxml2 vulnerabilities
osv·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Shinji Sato discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, and Ubuntu 16.04 ESM. (CVE-2022-23308)
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-29824)
GHSA
GHSA-3rrw-pv9w-qgch: In libxml2 before 2
ghsa_unreviewed·2022-05-04
CVE-2022-29824 [MEDIUM] CWE-190 GHSA-3rrw-pv9w-qgch: In libxml2 before 2
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
OSV
CVE-2022-29824: In libxml2 before 2
osv·2022-05-03·CVSS 6.5
CVE-2022-29824 [MEDIUM] CVE-2022-29824: In libxml2 before 2
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (libxml2) — CVE-2022-29824
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (libxml2) — CVE-2022-29824
Oracle Oracle Communications Risk Matrix: Install/Upgrade (libxml2) vulnerability
CVE: CVE-2022-29824
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (libxml2) — CVE-2022-29824
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2022-29824 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (libxml2) — CVE-2022-29824
Oracle Oracle Communications Risk Matrix: Configuration (libxml2) vulnerability
CVE: CVE-2022-29824
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-29824
vendor_chrome·2022-07-27·CVSS 6.5
CVE-2022-29824 [MEDIUM] Long Term Support Channel Update for ChromeOS: CVE-2022-29824
Long Term Support Channel Update for ChromeOS
CVE-2022-29824
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2022-05-16·CVSS 7.5
CVE-2022-29824 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
Shinji Sato discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, and Ubuntu 16.04 ESM. (CVE-2022-23308)
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-29824)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
In libxml2 before 2.9.14 several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation re
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-29824 [MEDIUM] CWE-190 In libxml2 before 2.9.14 several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation re
In libxml2 before 2.9.14 several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted multi-gigabyte XML file. Other software using libxml2's buffer functions for example libxslt through 1.1.35 is affected as well.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work whic
Red Hat
libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write
vendor_redhat·2022-05-03·CVSS 6.5
CVE-2022-29824 [MEDIUM] CWE-787 libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write
libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
A flaw was found in the libxml2 library in functions used to manipulate the xmlBuf and the xmlBuffer types. A substantial input causes values to calculate buffer sizes to overflow, resulting in an out-of-bounds write.
Mitigation: Avoid passing large inputs to the libxml2 library.
Package: libxml2 (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2022-29824: libxml2 - In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) a...
vendor_debian·2022·CVSS 6.5
CVE-2022-29824 [MEDIUM] CVE-2022-29824: libxml2 - In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) a...
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Scope: local
bookworm: resolved (fixed in 2.9.14+dfsg-1)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u2)
forky: resolved (fixed in 2.9.14+dfsg-1)
sid: resolved (fixed in 2.9.14+dfsg-1)
trixie: resolved (fixed in 2.9.14+dfsg-1)
No detection rules found.
Nuclei
Ivanti EPM - Remote Code Execution
nuclei·CVSS 8.8
CVE-2024-29824 [HIGH] Ivanti EPM - Remote Code Execution
Ivanti EPM - Remote Code Execution
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
Template:
id: CVE-2024-29824
info:
name: Ivanti EPM - Remote Code Execution
author: DhiyaneshDK
severity: critical
description: |
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
impact: |
Attackers can execute arbitrary code on the Ivanti EPM server, leading to complete system compromise.
remediation: |
Apply security updates for Ivanti EPM that address CVE-2024-29824.
reference:
- https://github.com/horizon3ai/CVE-2024-29824
- https://nvd.nist.gov/vu
No writeups or analysis indexed.
http://packetstormsecurity.com/files/167345/libxml2-xmlBufAdd-Heap-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/169825/libxml2-xmlParseNameComplex-Integer-Overflow.htmlhttps://gitlab.gnome.org/GNOME/libxml2/-/commit/2554a2408e09f13652049e5ffb0d26196b02ebabhttps://gitlab.gnome.org/GNOME/libxml2/-/commit/6c283d83eccd940bcde15634ac8c7f100e3caefdhttps://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.9.14https://gitlab.gnome.org/GNOME/libxslt/-/tagshttps://lists.debian.org/debian-lts-announce/2022/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZOBT5Y6Y2QLDDX2HZGMV7MJMWGXORKK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3NVZVWFRBXBI3AKZZWUWY6INQQPQVSF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P5363EDV5VHZ5C77ODA43RYDCPMA7ARM/https://security.gentoo.org/glsa/202210-03https://security.netapp.com/advisory/ntap-20220715-0006/https://www.debian.org/security/2022/dsa-5142https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/167345/libxml2-xmlBufAdd-Heap-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/169825/libxml2-xmlParseNameComplex-Integer-Overflow.htmlhttps://gitlab.gnome.org/GNOME/libxml2/-/commit/2554a2408e09f13652049e5ffb0d26196b02ebabhttps://gitlab.gnome.org/GNOME/libxml2/-/commit/6c283d83eccd940bcde15634ac8c7f100e3caefdhttps://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.9.14https://gitlab.gnome.org/GNOME/libxslt/-/tagshttps://lists.debian.org/debian-lts-announce/2022/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZOBT5Y6Y2QLDDX2HZGMV7MJMWGXORKK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3NVZVWFRBXBI3AKZZWUWY6INQQPQVSF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P5363EDV5VHZ5C77ODA43RYDCPMA7ARM/https://security.gentoo.org/glsa/202210-03https://security.netapp.com/advisory/ntap-20220715-0006/https://www.debian.org/security/2022/dsa-5142https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-03
Published