libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
References
Link | Resource |
---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 | Issue Tracking |
https://issues.oss-fuzz.com/issues/392687022 | Issue Tracking |
https://security.netapp.com/advisory/ntap-20250321-0006/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
16 Oct 2025, 19:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
|
References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 - Issue Tracking | |
References | () https://issues.oss-fuzz.com/issues/392687022 - Issue Tracking | |
References | () https://security.netapp.com/advisory/ntap-20250321-0006/ - Third Party Advisory | |
First Time |
Netapp hci Compute Node
Netapp h500s Netapp h410c Firmware Netapp h700s Firmware Netapp active Iq Unified Manager Netapp h410s Firmware Netapp Netapp ontap Xmlsoft Netapp h410c Xmlsoft libxml2 Netapp h500s Firmware Netapp h410s Netapp solidfire \& Hci Management Node Netapp h700s Netapp h300s Netapp h300s Firmware Netapp manageability Software Development Kit |
21 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
18 Feb 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-18 23:15
Updated : 2025-10-16 19:34
NVD link : CVE-2025-24928
Mitre link : CVE-2025-24928
CVE.ORG link : CVE-2025-24928
JSON object : View
Products Affected
netapp
- h410s_firmware
- h410c
- hci_compute_node
- h500s_firmware
- h300s
- h500s
- h700s
- solidfire_\&_hci_management_node
- h410c_firmware
- manageability_software_development_kit
- h300s_firmware
- h700s_firmware
- active_iq_unified_manager
- h410s
- ontap
xmlsoft
- libxml2
CWE
CWE-121
Stack-based Buffer Overflow