logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-29824

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-29824

Description:
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Last updated date:
01/11/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/22/2022
Reference url to background

http://packetstormsecurity.com/files/167345/libxml2-xmlBufAdd-Heap-Buffer-Overflow.html

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/11/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy