CVE-2024-34459

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bullseye
unimportant
bullseye (security)
unimportant
bookworm
unimportant
sid
2.12.7+dfsg+really2.9.14-1
fixed
trixie
2.12.7+dfsg+really2.9.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml2
oracular
not-affected
noble
Fixed 2.9.14+dfsg-1.3ubuntu3.1
released
mantic
ignored
jammy
Fixed 2.9.13+dfsg-1ubuntu0.5
released
focal
Fixed 2.9.10+dfsg-5ubuntu0.20.04.8
released
bionic
Fixed 2.9.4+dfsg1-6.1ubuntu1.9+esm2
released
xenial
Fixed 2.9.3+dfsg1-1ubuntu0.7+esm7
released
trusty
ignored