Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libxml2 拒绝服务漏洞
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 Libxml2的parser.c文件中的‘xmlParseConditionalSections’函数中存在安全漏洞,该漏洞源于程序停止解析无效输入时没有正确跳过中间实体。攻击者可借助特制的XML数据利用该漏洞造成拒绝服务(越边界读取和崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A