Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-25062

Description

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

POC

Reference

No PoCs from references.

Github

- https://github.com/11notes/docker-paperless-ngx

- https://github.com/CodingSimia/jenkins-shiftleft

- https://github.com/OzNetNerd/CheckovOutputProcessor

- https://github.com/bygregonline/devsec-fastapi-report

- https://github.com/drewtwitchell/scancompare

- https://github.com/lucacome/lucacome

- https://github.com/ndouglas-cloudsmith/exploit-check

- https://github.com/poikl246/DevSecOps-2024-v2

- https://github.com/robertsirc/sle-bci-demo

- https://github.com/runwhen-contrib/helm-charts

- https://github.com/w4zu/Debian_security