Lucene search

K
redosRedosROS-20240410-16
HistoryApr 10, 2024 - 12:00 a.m.

ROS-20240410-16

2024-04-1000:00:00
redos.red-soft.ru
12
xml validation memory usage
denial of service
remote attack
libxml2 vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

A vulnerability in the xmlValidatePopElement function of the XML Reader Interface component of the Libxml2 library is related to the
memory usage after it has been freed. Exploitation of the vulnerability could allow an attacker,
acting remotely, to cause a denial of service using a specially crafted file

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64libxml2<= 2.9.8-15UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%