libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
References
| Link | Resource |
|---|---|
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 | Issue Tracking |
| https://issues.oss-fuzz.com/issues/392687022 | Issue Tracking |
| https://security.netapp.com/advisory/ntap-20250321-0006/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
History
16 Oct 2025, 19:34
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netapp active Iq Unified Manager
Netapp h500s Netapp h410c Firmware Netapp h410c Netapp h500s Firmware Netapp h700s Firmware Netapp manageability Software Development Kit Xmlsoft Xmlsoft libxml2 Netapp solidfire \& Hci Management Node Netapp Netapp h410s Netapp h700s Netapp h300s Firmware Netapp h300s Netapp h410s Firmware Netapp hci Compute Node Netapp ontap |
|
| CPE | cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
|
| References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 - Issue Tracking | |
| References | () https://issues.oss-fuzz.com/issues/392687022 - Issue Tracking | |
| References | () https://security.netapp.com/advisory/ntap-20250321-0006/ - Third Party Advisory |
21 Mar 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
18 Feb 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-18 23:15
Updated : 2025-10-16 19:34
NVD link : CVE-2025-24928
Mitre link : CVE-2025-24928
CVE.ORG link : CVE-2025-24928
JSON object : View
Products Affected
netapp
- h500s_firmware
- active_iq_unified_manager
- hci_compute_node
- h410c_firmware
- h410c
- h300s_firmware
- h700s_firmware
- h410s
- h500s
- h700s
- manageability_software_development_kit
- h300s
- solidfire_\&_hci_management_node
- h410s_firmware
- ontap
xmlsoft
- libxml2
CWE
CWE-121
Stack-based Buffer Overflow
