CVE-2024-34392
02.05.2024, 19:15
libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
Vendor | Product | Version |
---|---|---|
libxmljs_project | libxmljs | 𝑥 ≤ 1.0.11 |
𝑥
= Vulnerable software versions
References