CVE-2022-40304 is a high-severity vulnerability in libxml2 versions prior to 2.10.3, affecting products like Apple and NetApp. Invalid XML entity definitions can corrupt a hash table key, potentially leading to logic errors and a double-free condition. This vulnerability has a CVSS score of 7.8, indicating a high impact on confidentiality, integrity, and availability, with a low attack complexity requiring user interaction. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness among researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.3CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
June Third Party Package Updates in Splunk Cloud
Jun 1, 2023An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key potentially leading to subsequent logic errors. In one case a double-free can be provoked.
Nov 8, 2022libxml2: dict corruption caused by entity reference cycles
Oct 14, 2022libxml2 vulnerabilities
libxml2 vulnerabilities (CVE-2022-40303, CVE-2022-40304)
libxml2 vulnerabilities
libxml2 Vulnerabilities
libxml2 vulnerabilities resolved
libxml2 vulnerabilities
libxml2 vulnerabilities