CVE

CVE-2022-23308

Severity:
HIGH
Type:
CWE-416 Use After Free
Publication date:
26/02/2022
Last modified:
02/11/2022

Description

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Vulnerable products and versions

  • cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
  • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*