CVE-2024-34393
🟡 Monitoruj
Typowe pomieszanie typów w libxmljs2 może prowadzić do zdalnego wykonania kodu i odmowy usługi.
CVSS
8.1
EPSS
1.0%
Exploit
none
Vendor
Opis źródłowy (NVD)
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).
dos rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.0% |
| Opublikowano (NVD) | 2024-05-02 19:15:06 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 09:17:03 UTC |
Referencje
- https://research.jfrog.com/vulnerabilities/libxmljs2-attrs-type-confusion-rce-jfsa-2024-001034097/ ([email protected])
- https://github.com/marudor/libxmljs2/issues/204 (af854a3a-2127-422b-91ae-364da2661108)