Vulnerability Description
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | < 2.11.7 |
Related Weaknesses (CWE)
References
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/604ExploitIssue Tracking
- https://gitlab.gnome.org/GNOME/libxml2/-/tagsRelease Notes
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/604ExploitIssue Tracking
- https://gitlab.gnome.org/GNOME/libxml2/-/tagsRelease Notes
- https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html
- https://security.netapp.com/advisory/ntap-20241018-0009/
FAQ
What is CVE-2024-25062?
CVE-2024-25062 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can ...
How severe is CVE-2024-25062?
CVE-2024-25062 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-25062?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2.