-
Notifications
You must be signed in to change notification settings - Fork 47
Closed
Labels
advisorysecurity advisorysecurity advisorycvss/CRITICAL>= 9 assessed CVSS>= 9 assessed CVSSsecuritysecurity concernssecurity concerns
Description
Name: libxml2
CVEs: CVE-2024-40896
CVSSs: 9.1
Action Needed: update to >= 2.12.9
Summary: In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
refmap.gentoo: https://bugs.gentoo.org/943198
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
advisorysecurity advisorysecurity advisorycvss/CRITICAL>= 9 assessed CVSS>= 9 assessed CVSSsecuritysecurity concernssecurity concerns