HIGH · 8.6

CVE-2021-3517

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affect...

Vulnerability Description

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
XmlsoftLibxml2< 2.9.11
RedhatJboss Core Services-
RedhatEnterprise Linux8.0
FedoraprojectFedora33
DebianDebian Linux9.0
NetappActive Iq Unified Manager-
NetappClustered Data Ontap-
NetappClustered Data Ontap Antivirus Connector-
NetappE-Series Santricity Os Controller>= 11.0.0, <= 11.70.1
NetappE-Series Santricity Storage Manager-
NetappE-Series Santricity Web Services-
NetappHci Management Node-
NetappManageability Software Development Kit-
NetappOncommand Insight-
NetappOncommand Workflow Automation-
NetappOntap Select Deploy Administration Utility-
NetappSantricity Unified Manager-
NetappSnapdrive-
NetappSnapmanager-
NetappSolidfire-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3517?

CVE-2021-3517 is a vulnerability with a CVSS score of 8.6 (HIGH). There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affect...

How severe is CVE-2021-3517?

CVE-2021-3517 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3517?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Redhat Jboss Core Services, Redhat Enterprise Linux, Fedoraproject Fedora, Debian Debian Linux.