Use-After-Free Vulnerability in libxml2 by GNOME
CVE-2023-45322
6.5MEDIUM
What is CVE-2023-45322?
A use-after-free vulnerability exists in libxml2 versions up to 2.11.5, specifically in the xmlUnlinkNode function located in tree.c. This vulnerability may be triggered after a failed memory allocation, potentially leading to abnormal program behavior. Although the vendor suggests the risk is limited due to the nature of how memory allocation failures are handled, it remains crucial for users to assess their exposure and apply necessary security measures.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
