8.6

CVE-2021-3517

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xmlsoft ≫ Libxml2 Version < 2.9.11
Redhat ≫ Jboss Core Services Version -
Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.70.1
Netapp ≫ E-series Santricity Web Services Version - SwPlatform web_services_proxy
Netapp ≫ Hci Management Node Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Snapdrive Version - SwPlatform windows
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Netapp ≫ Solidfire Version -
Netapp ≫ Hci H410c Firmware Version -
   Netapp ≫ Hci H410c Version -
Oracle ≫ Mysql Workbench Version <= 8.0.26
Oracle ≫ Openjdk Version 8 Update update301
Oracle ≫ Real User Experience Insight Version 13.4.1.0
Oracle ≫ Real User Experience Insight Version 13.5.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.28% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
https://www.oracle.com/security-alerts/cpujul2022.html
Not Applicable
https://security.gentoo.org/glsa/202107-05
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
https://security.netapp.com/advisory/ntap-20210625-0002/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1954232
Patch
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20211022-0004/
Third Party Advisory