CVE-2021-3518
high · 8.8There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
8.8
CVSS
21.9%
EPSS (exploit prob.)
98th
EPSS percentile
2021-05-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| xmlsoft | libxml2 | < 2.9.11 |
| debian | debian_linux | 9.0 |
| redhat | jboss_core_services | all versions |
| redhat | enterprise_linux | 8.0 |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| netapp | active_iq_unified_manager | all versions |
| netapp | clustered_data_ontap | all versions |
| netapp | clustered_data_ontap_antivirus_connector | all versions |
| netapp | manageability_software_development_kit | all versions |
| netapp | ontap_select_deploy_administration_utility | all versions |
| netapp | snapdrive | all versions |
| netapp | hci_h410c_firmware | all versions |
| netapp | hci_h410c | all versions |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | enterprise_manager_base_platform | 13.5.0.0 |
| oracle | enterprise_manager_ops_center | 12.4.0.0 |
| oracle | mysql_workbench | <= 8.0.26 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | real_user_experience_insight | 13.4.1.0 |
| oracle | real_user_experience_insight | 13.5.1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2021/Jul/54
- http://seclists.org/fulldisclosure/2021/Jul/55
- http://seclists.org/fulldisclosure/2021/Jul/58
- http://seclists.org/fulldisclosure/2021/Jul/59
- https://bugzilla.redhat.com/show_bug.cgi?id=1954242
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZOMV5J4PMZAORVT64BKLV6YIZAFDGX6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/
- https://security.gentoo.org/glsa/202107-05
- https://security.netapp.com/advisory/ntap-20210625-0002/
- https://support.apple.com/kb/HT212601
- https://support.apple.com/kb/HT212602
- https://support.apple.com/kb/HT212604
- https://support.apple.com/kb/HT212605
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- http://seclists.org/fulldisclosure/2021/Jul/54
- http://seclists.org/fulldisclosure/2021/Jul/55
- http://seclists.org/fulldisclosure/2021/Jul/58
- http://seclists.org/fulldisclosure/2021/Jul/59
- https://bugzilla.redhat.com/show_bug.cgi?id=1954242
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-3518