Logo
componentperl-xml-libxml
Name
perl-xml-libxml
Version
2.0134
Type
library
Description
-
Licenses
Artistic or GPL-1.0+
PURL
pkg:cpan/SHLOMIF/@2.0134
CPE
cpe:2.3:a:xml-libxml_project:xml-libxml:2.0134:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
2.0134

Patches#


#
Title
Author
Resolve
1
Patch #1
Francois Perrad <francois.perrad@gadz.org>

Vulnerabilities#


Name
Analysis
Description
Exploitable
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.