In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
References
Link | Resource |
---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/issues/491 | Exploit Issue Tracking Patch Vendor Advisory |
https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4 | Release Notes |
https://lists.debian.org/debian-lts-announce/2023/04/msg00031.html | Mailing List Third Party Advisory |
https://security.netapp.com/advisory/ntap-20230601-0006/ | |
https://security.netapp.com/advisory/ntap-20240201-0005/ |
Configurations
History
01 Feb 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jun 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 May 2023, 20:23
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-476 | |
CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/04/msg00031.html - Mailing List, Third Party Advisory | |
References | (MISC) https://gitlab.gnome.org/GNOME/libxml2/-/issues/491 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
References | (MISC) https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4 - Release Notes |
30 Apr 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Apr 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-24 21:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-28484
Mitre link : CVE-2023-28484
CVE.ORG link : CVE-2023-28484
JSON object : View
Products Affected
debian
- debian_linux
xmlsoft
- libxml2
CWE
CWE-476
NULL Pointer Dereference