CVE-2021-3518

Description

Theres a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.23

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-20227,CVE-2021-3518,CVE-2021-3712 are affected in MySQL Workbench Enterprise Edition 8.0.26Windows
Vulnerabilities CVE-2021-20227,CVE-2021-3518,CVE-2021-3712 are affected in MySQL Workbench CE (x64) 8.0.26Windows
Vulnerabilities CVE-2021-3517,CVE-2021-3518,CVE-2021-3537 are fixed in Ruby-nokogiri 1.11.4Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple vulnerabilities are fixed in MacOS Big Sur 11.5 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.5.1 - Software Update (CVE-2021-30807)Mac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.5.2 - Software UpdateMac
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-32bit-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-debuginfo-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-debuginfo-32bit-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-debugsource-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-doc-2.9.4-46.40.1.noarch.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-tools-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-tools-debuginfo-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-debuginfo-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1524-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-debugsource-2.9.4-46.40.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-32bit-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-debuginfo-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-2-debuginfo-32bit-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-debugsource-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-doc-2.9.4-46.43.1.noarch.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-tools-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) libxml2-tools-debuginfo-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-debuginfo-2.9.4-46.43.1.x86_64.rpmLinux
SUSE-SU-2021:1658-1(SUSE Linux Enterprise Server 12-SP5 ) python-libxml2-debugsource-2.9.4-46.43.1.x86_64.rpmLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-6.3ubuntu0.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-6.3ubuntu0.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.4+dfsg1-6.1ubuntu1.4_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.4+dfsg1-6.1ubuntu1.4_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.04.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.04.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.10.2_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.10.2_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.4_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.4_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.10.2_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.10.2_amd64.debLinux
Libxml2 update (ELSA-2021-2569) libxml2-2.9.7-9.0.1.el8_4.2.i686.rpmLinux
Libxml2 update (ELSA-2021-2569) libxml2-2.9.7-9.0.1.el8_4.2.x86_64.rpmLinux
Libxml2-devel update (ELSA-2021-2569) libxml2-devel-2.9.7-9.0.1.el8_4.2.i686.rpmLinux
Libxml2-devel update (ELSA-2021-2569) libxml2-devel-2.9.7-9.0.1.el8_4.2.x86_64.rpmLinux
Python3-libxml2 update (ELSA-2021-2569) python3-libxml2-2.9.7-9.0.1.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-2.9.7-9.el8_4.2.i686.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-2.9.7-9.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-debugsource-2.9.7-9.el8_4.2.i686.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-debugsource-2.9.7-9.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-devel-2.9.7-9.el8_4.2.i686.rpmLinux
(RHSA-2021:2569) libxml2 security update libxml2-devel-2.9.7-9.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2569) libxml2 security update python3-libxml2-2.9.7-9.el8_4.2.x86_64.rpmLinux
Libxml2 update (ELSA-2022-0899) libxml2-2.9.7-12.el8_5.i686.rpmLinux
Libxml2 update (ELSA-2022-0899) libxml2-2.9.7-12.el8_5.x86_64.rpmLinux
Libxml2-devel update (ELSA-2022-0899) libxml2-devel-2.9.7-12.el8_5.i686.rpmLinux
Libxml2-devel update (ELSA-2022-0899) libxml2-devel-2.9.7-12.el8_5.x86_64.rpmLinux
Python3-libxml2 update (ELSA-2022-0899) python3-libxml2-2.9.7-12.el8_5.x86_64.rpmLinux
Vulnerabilities CVE-2021-3517,CVE-2021-3518,CVE-2021-3537 are fixed in Ruby-nokogiri for Linux 1.11.4Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-347137MySQL Workbench CE (x64) (8.0.42)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234