SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-29469

An issue was discovered in libxml2 before 2.10.4.

MEDIUM 6.5EPSS 1.00%

Does this matter?

Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-415
Affected
xmlsoft/libxml2 · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.