Logo
vulnerabilityCVE-2022-29824
Name
CVE-2022-29824
Source
NVD ( link)Debian ( link)
Description
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libxslt
False Positive

Vulnerability Ratings#


6.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.1.45
Not Affected
buildroot
master
1.1.45
Not Affected
openwrt
master
1.1.42-r1
Not Affected
openwrt
openwrt-25.12
1.1.42-r1
Not Affected
yocto
kirkstone
1.1.35
Not Affected
yocto
master
1.1.45
Not Affected