Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libxml2‘xmlNextChar’函数
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 libxml2 2.9.2版本的‘xmlNextChar’函数中存在安全漏洞,该漏洞源于程序没有正确检查状态。攻击者可借助特制的XML数据利用该漏洞造成拒绝服务(基于堆的缓冲区越边界读取和应用程序崩溃),或获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A