Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libxml2 信息泄露漏洞
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 libxml2 2.9.3之前版本的parser.c文件中的‘xmlParseXMLDecl’函数存在安全漏洞。攻击者可借助XML数据中未终止的编码值和未完成的XML声明利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A