CVE-2023-39615: Buffer Overflow
DISPUTED Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.
Other sources
Xmlsoft Libxml2 is vulnerable to a denial of service, caused by a global buffer overflow in the xmlSAX2StartElement() function at /libxml2/SAX2.c. By supplying a crafted XML file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Xmlsoft Libxml2 v2.11.0 was discovered to contain a global buffer overflow via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file.
https://gitlab.gnome.org/GNOME/libxml2/-/issues/535
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for Xmlsoft Libxml2 v2.11.0?
The vulnerability ID for Xmlsoft Libxml2 v2.11.0 is CVE-2023-39615.
What is the severity of CVE-2023-39615?
The severity of CVE-2023-39615 is medium with a CVSS score of 6.5.
How can attackers exploit CVE-2023-39615?
Attackers can exploit CVE-2023-39615 by supplying a crafted XML file to the xmlSAX2StartElement() function, causing an out-of-bounds read and potentially leading to a Denial of Service (DoS) attack.
What is the affected software for CVE-2023-39615?
The affected software for CVE-2023-39615 is Xmlsoft Libxml2 v2.11.0.
Is there a fix available for CVE-2023-39615?
At the moment, there is no fix available for CVE-2023-39615. It is recommended to follow the vendor's updates and patches for any developments.