CVE-2022-40304

Name
CVE-2022-40304
Description
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
MISC https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b
MISC https://gitlab.gnome.org/GNOME/libxml2/-/tags
Third Party Advisory https://security.netapp.com/advisory/ntap-20221209-0003/
Third Party Advisory https://support.apple.com/kb/HT213534
Third Party Advisory https://support.apple.com/kb/HT213535
Third Party Advisory https://support.apple.com/kb/HT213536
Third Party Advisory https://support.apple.com/kb/HT213531
Third Party Advisory https://support.apple.com/kb/HT213533
Mailing List http://seclists.org/fulldisclosure/2022/Dec/21
Mailing List http://seclists.org/fulldisclosure/2022/Dec/25
Mailing List http://seclists.org/fulldisclosure/2022/Dec/24
Mailing List http://seclists.org/fulldisclosure/2022/Dec/26
http://seclists.org/fulldisclosure/2022/Dec/27

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* libxml2 >= None < 2.10.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxml2 3.16-main 2.9.14-r2 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.15-main 2.9.14-r2 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.14-main 2.9.14-r2 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.13-main 2.9.14-r2 Carlo Landmeter <clandmeter@alpinelinux.org> fixed