CVE-2025-8732

EUVD-2025-24001
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxml2-2
suse enterprise desktop 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise server 12 SP3
2.9.4-46.93.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.11.1
fixed
libxml2-2-32bit
suse enterprise desktop 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise server 12 SP3
2.9.4-46.93.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.11.1
fixed
libxml2-devel
suse enterprise desktop 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.11.1
fixed
libxml2-doc
suse enterprise server 12 SP3
2.9.4-46.93.1
fixed
libxml2-tools
suse enterprise desktop 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise server 12 SP3
2.9.4-46.93.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.11.1
fixed
python-libxml2
suse enterprise server 12 SP3
2.9.4-46.93.1
fixed
python3-libxml2
suse enterprise desktop 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.11.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.11.1
fixed
python311-libxml2
suse enterprise server 15 SP4
2.9.14-150400.5.50.1
fixed