** DISPUTED ** libxml2 through 2.11.5 has a use-after...
Moderate severity
Unreviewed
Published
Oct 7, 2023
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Oct 6, 2023
Published to the GitHub Advisory Database
Oct 7, 2023
Last updated
Mar 21, 2024
** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
References