CVE-2025-32414

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
References
Link Resource
https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 Exploit Issue Tracking Patch
https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

23 Apr 2025, 19:09

Type Values Removed Values Added
First Time Xmlsoft libxml2
Xmlsoft
CWE CWE-252
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 - Exploit, Issue Tracking, Patch
CPE cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

09 Apr 2025, 15:16

Type Values Removed Values Added
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/889 -

08 Apr 2025, 18:13

Type Values Removed Values Added
Summary
  • (es) En libxml2 anterior a la versión 2.13.8 y 2.14.x anterior a la versión 2.14.2, se pueden producir accesos a memoria fuera de los límites en la API de Python (enlaces de Python) debido a un valor de retorno incorrecto. Esto ocurre en xmlPythonFileRead y xmlPythonFileReadRaw debido a una diferencia entre bytes y caracteres.

08 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 03:15

Updated : 2025-04-23 19:09


NVD link : CVE-2025-32414

Mitre link : CVE-2025-32414

CVE.ORG link : CVE-2025-32414


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-393

Return of Wrong Status Code

CWE-252

Unchecked Return Value