Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-29469
HistoryApr 12, 2023 - 12:00 a.m.

CVE-2023-29469

2023-04-1200:00:00
ubuntu.com
ubuntu.com
38
cve-2023-29469; libxml2; xml document

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

46.5%

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict
strings in a crafted XML document, xmlDictComputeFastKey in dict.c can
produce non-deterministic values, leading to various logic and memory
errors, such as a double free. This behavior occurs because there is an
attempt to use the first byte of an empty string, and any value is possible
(not solely the ‘\0’ value).

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlibxml2< 2.9.4+dfsg1-6.1ubuntu1.9UNKNOWN
ubuntu20.04noarchlibxml2< 2.9.10+dfsg-5ubuntu0.20.04.6UNKNOWN
ubuntu22.04noarchlibxml2< 2.9.13+dfsg-1ubuntu0.3UNKNOWN
ubuntu22.10noarchlibxml2< 2.9.14+dfsg-1ubuntu0.2UNKNOWN
ubuntu23.04noarchlibxml2< 2.9.14+dfsg-1.1ubuntu0.1UNKNOWN
ubuntu14.04noarchlibxml2< 2.9.1+dfsg1-3ubuntu4.13+esm5UNKNOWN
ubuntu16.04noarchlibxml2< 2.9.3+dfsg1-1ubuntu0.7+esm5UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

46.5%