Use-After-Free Vulnerability in libxml2 by GNOME
CVE-2023-45322

6.5MEDIUM

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
6 October 2023

What is CVE-2023-45322?

A use-after-free vulnerability exists in libxml2 versions up to 2.11.5, specifically in the xmlUnlinkNode function located in tree.c. This vulnerability may be triggered after a failed memory allocation, potentially leading to abnormal program behavior. Although the vendor suggests the risk is limited due to the nature of how memory allocation failures are handled, it remains crucial for users to assess their exposure and apply necessary security measures.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-45322 : Use-After-Free Vulnerability in libxml2 by GNOME