CVE-2024-25062: Use After Free
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25062?
CVE-2024-25062 is classified as a high severity vulnerability due to the potential for exploitation through crafted XML documents.
How do I fix CVE-2024-25062?
To address CVE-2024-25062, upgrade libxml2 to version 2.12.7 or later, or to 2.12.5 from Red Hat's distribution.
Which versions of libxml2 are affected by CVE-2024-25062?
Versions of libxml2 before 2.11.7 and between 2.12.0 and 2.12.5 are affected by CVE-2024-25062.
What type of vulnerability is CVE-2024-25062?
CVE-2024-25062 is a use-after-free vulnerability that occurs during XML processing with DTD validation and XInclude expansion.
Is CVE-2024-25062 exploitable remotely?
Yes, CVE-2024-25062 can be remotely exploited when processing maliciously crafted XML documents.