CVE-2024-56171

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Configurations

No configuration.

History

28 Mar 2025, 15:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250328-0010/ -
Summary
  • (es) libxml2 antes de 2.12.10 y 2.13.x antes de 2.13.6 tiene un use-after-free en xmlschemaidcfillNodetable y xmlschemabubbleIdcnodetable en xmlschemas.c. Para explotar esto, un documento XML manipulado debe validarse contra un esquema XML con ciertas restricciones de identidad manipulado El esquema XML manipulado debe usarse.

18 Feb 2025, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-416

18 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 22:15

Updated : 2025-03-28 15:15


NVD link : CVE-2024-56171

Mitre link : CVE-2024-56171

CVE.ORG link : CVE-2024-56171


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free