Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libxml2 信息泄露漏洞
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 libxml2 2.9.3之前版本的HTML解析器中的push接口的SAX2.c文件中的‘xmlSAX2TextNode’函数存在安全漏洞。攻击者可借助特制的XML数据利用该漏洞造成拒绝服务(基于栈的缓冲区越边界读取和应用程序崩溃),或获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A