CVE-2021-3517
Last modified
CVE-2021-3517 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. EPSS estimates a 8.28% chance of exploitation in the next 30 days.
Description
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Xmlsoft | Libxml2 | < 2.9.11 | — |
| Redhat | Jboss Core Services | All versions | — |
| Redhat | Enterprise Linux | 8.0 | — |
| Fedoraproject | Fedora | 33 | — |
| Fedoraproject | Fedora | 34 | — |
| Debian | Debian Linux | 9.0 | — |
| Netapp | Active Iq Unified Manager | All versions | — |
| Netapp | Clustered Data Ontap | All versions | — |
| Netapp | Clustered Data Ontap Antivirus Connector | All versions | — |
| Netapp | E-Series Santricity Os Controller | >= 11.0.0, <= 11.70.1 | — |
| Netapp | E-Series Santricity Storage Manager | All versions | — |
| Netapp | E-Series Santricity Web Services | All versions | — |
| Netapp | Hci Management Node | All versions | — |
| Netapp | Manageability Software Development Kit | All versions | — |
| Netapp | Oncommand Insight | All versions | — |
| Netapp | Oncommand Workflow Automation | All versions | — |
| Netapp | Ontap Select Deploy Administration Utility | All versions | — |
| Netapp | Santricity Unified Manager | All versions | — |
| Netapp | Snapdrive | All versions | — |
| Netapp | Snapmanager | All versions | — |
| Netapp | Solidfire | All versions | — |
| Netapp | Hci H410c Firmware | All versions | — |
| Oracle | Communications Cloud Native Core Network Function Cloud Native Environment | 1.10.0 | — |
| Oracle | Enterprise Manager Base Platform | 13.4.0.0 | — |
| Oracle | Enterprise Manager Base Platform | 13.5.0.0 | — |
| Oracle | Mysql Workbench | <= 8.0.26 | — |
| Oracle | Openjdk | 8 | Update301 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.58 | — |
| Oracle | Real User Experience Insight | 13.4.1.0 | — |
| Oracle | Real User Experience Insight | 13.5.1.0 | — |
| Oracle | Zfs Storage Appliance Kit | 8.8 | — |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1954232Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211022-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlNot Applicable
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954232Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210625-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211022-0004/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlNot Applicable
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3517?
How severe is CVE-2021-3517?
How do I fix CVE-2021-3517?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35133Use after free in the synx driver issue while performing oth…6.7
- CVE-2021-35134Due to insufficient validation of ELF headers, an Incorrect …8.4
- CVE-2021-35135A null pointer dereference may potentially occur during RSA …5.5
- CVE-2021-3514When using a sync_repl client in 389-ds-base, an authenticat…6.5
- CVE-2021-3515A shell injection flaw was found in pglogical in versions be…6.7
- CVE-2021-3516There's a flaw in libxml2's xmllint in versions before 2.9.1…7.8
- CVE-2021-3518There's a flaw in libxml2 in versions before 2.9.11. An atta…8.8
- CVE-2021-3519A vulnerability was reported in some Lenovo Desktop models t…6.8
- CVE-2021-35193Patterson Application Service in Patterson Eaglesoft 18 thro…7.5
- CVE-2021-35196Manuskript through 0.12.0 allows remote attackers to execute…7.8
- CVE-2021-35197In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.…7.5
- CVE-2021-35198NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stor…5.4
Are you affected by CVE-2021-3517?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
