MEDIUM · 6.5

CVE-2022-29824

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation r...

Vulnerability Description

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
XmlsoftLibxml2< 2.9.14
XmlsoftLibxslt<= 1.1.35
FedoraprojectFedora34
DebianDebian Linux9.0
NetappActive Iq Unified Manager-
NetappClustered Data Ontap-
NetappClustered Data Ontap Antivirus Connector-
NetappManageability Software Development Kit-
NetappOntap Select Deploy Administration Utility-
NetappSmi-S Provider-
NetappSnapdrive-
NetappSnapmanager-
NetappSolidfire \& Hci Management Node-
OracleZfs Storage Appliance Kit8.8
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29824?

CVE-2022-29824 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation r...

How severe is CVE-2022-29824?

CVE-2022-29824 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29824?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Xmlsoft Libxslt, Fedoraproject Fedora, Debian Debian Linux, Netapp Active Iq Unified Manager.