CVE-2021-3517
Last modified
CVE-2021-3517 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. EPSS estimates a 8.28% chance of exploitation in the next 30 days.
Description
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Xmlsoft | Libxml2 | < 2.9.11 | — |
| Redhat | Jboss Core Services | All versions | — |
| Redhat | Enterprise Linux | 8.0 | — |
| Fedoraproject | Fedora | 33 | — |
| Fedoraproject | Fedora | 34 | — |
| Debian | Debian Linux | 9.0 | — |
| Netapp | Active Iq Unified Manager | All versions | — |
| Netapp | Clustered Data Ontap | All versions | — |
| Netapp | Clustered Data Ontap Antivirus Connector | All versions | — |
| Netapp | E-Series Santricity Os Controller | >= 11.0.0, <= 11.70.1 | — |
| Netapp | E-Series Santricity Storage Manager | All versions | — |
| Netapp | E-Series Santricity Web Services | All versions | — |
| Netapp | Hci Management Node | All versions | — |
| Netapp | Manageability Software Development Kit | All versions | — |
| Netapp | Oncommand Insight | All versions | — |
| Netapp | Oncommand Workflow Automation | All versions | — |
| Netapp | Ontap Select Deploy Administration Utility | All versions | — |
| Netapp | Santricity Unified Manager | All versions | — |
| Netapp | Snapdrive | All versions | — |
| Netapp | Snapmanager | All versions | — |
| Netapp | Solidfire | All versions | — |
| Netapp | Hci H410c Firmware | All versions | — |
| Oracle | Communications Cloud Native Core Network Function Cloud Native Environment | 1.10.0 | — |
| Oracle | Enterprise Manager Base Platform | 13.4.0.0 | — |
| Oracle | Enterprise Manager Base Platform | 13.5.0.0 | — |
| Oracle | Mysql Workbench | <= 8.0.26 | — |
| Oracle | Openjdk | 8 | Update301 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.58 | — |
| Oracle | Real User Experience Insight | 13.4.1.0 | — |
| Oracle | Real User Experience Insight | 13.5.1.0 | — |
| Oracle | Zfs Storage Appliance Kit | 8.8 | — |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1954232Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211022-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlNot Applicable
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954232Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211022-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlNot Applicable
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3517?
How severe is CVE-2021-3517?
How do I fix CVE-2021-3517?
Are you affected by CVE-2021-3517?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
