CVE-2021-3517
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Exploitability: 3.9 / Impact: 4.7
Source: NVD
Description
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Affected (33)
Products: Xmlsoft: Libxml2 · Redhat: Enterprise Linux, Jboss Core Services · Fedoraproject: Fedora · +3 more
Show all products
Xmlsoft: Libxml2 · Redhat: Enterprise Linux, Jboss Core Services · Fedoraproject: Fedora · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Clustered Data Ontap, Clustered Data Ontap Antivirus Connector, E Series Santricity Os Controller, E Series Santricity Storage Manager, E Series Santricity Web Services, Hci Management Node, Manageability Software Development Kit, Oncommand Insight, Oncommand Workflow Automation, Ontap Select Deploy Administration Utility, Santricity Unified Manager, Snapdrive, Snapmanager, Solidfire, Hci H410c Firmware · Oracle: Communications Cloud Native Core Network Function Cloud Native Environment, Enterprise Manager Base Platform, Mysql Workbench, Openjdk, Peoplesoft Enterprise Peopletools, Real User Experience Insight, Zfs Storage Appliance Kit
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| From 11.0.0 to 11.70.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci H410c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.10.0 | |
| Version 13.4.0.0 | |
| Up to 8.0.26 | |
| Version 8 update301 | |
| Version 8.58 | |
| Version 13.4.1.0 | |
| Version 8.8 |
Related CWEs
References (26)
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.