A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGML
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
별도 긴급 패치 불필요 — 정기 시스템 업그레이드 주기에 맞춰 조치
CVSS 벡터 · 메트릭
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L상세 설명
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- xmlsoft libxml2< 2.15.2other
- siemens ruggedcom_rst2428p_firmware< 4.0other
- siemens ruggedcom_rst2428pother
- ibm vios4.1.0 - 4.1.1.30other
- ibm viosother
- ibm aix7.2.5 - 7.2.5.12other
- ibm aix7.3.2 - 7.3.3.3other
- ibm aixother
영향받는 구성 (CPE) 7
- xmlsoft libxml2< 2.15.2cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
- siemens ruggedcom_rst2428p_firmware< 4.0cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:*
- siemens ruggedcom_rst2428pcpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*
- ibm vios≥ 4.1.0 < 4.1.1.30cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
- ibm vios 4.1.2.0cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
- ibm aix≥ 7.2.5 < 7.2.5.12cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
- ibm aix 7.3.4cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
참고 자료 7
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/958ExploitIssue TrackingThird Party Advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.319228Permissions RequiredThird Party Advisory
- https://vuldb.com/?id.319228Permissions RequiredThird Party Advisory
- https://vuldb.com/?submit.622285Permissions RequiredThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlThird Party Advisory
링크 내용 불러오는 중…