CVE-2024-25062
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Ibm Aix, Java Platform, Linuxmint
- Xmlsoft libxml2
- < 2.11.7, 2.12.5
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.4% (69th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2024-02-04
CVE-2024-25062 at NVD
2 known exploits for CVE-2024-25062
Proof-of-concept code and exploit modules indexed by Sploitus