CVE-2022-29824 vulnerability in Xmlsoft and Other Products
Published on May 3, 2022
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Github Repository
Vendor Advisory
Vendor Advisory
Vendor Advisory
Vendor Advisory
Vendor Advisory
NVD
Products Associated with CVE-2022-29824
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-29824 are published in these products:
Vulnerable Packages
The following package name and versions may be associated with CVE-2022-29824
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| rubygems | nokogiri | < 1.13.5 | 1.13.5 |
Exploit Probability
EPSS
0.07%
Percentile
22.36%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.