6.5
CVSSv3

CVE-2022-30045

Published: 17/05/2022 Updated: 25/05/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ezxml project ezxml 0.8.6

Vendor Advisories

Debian Bug report logs - #1014389 mapcache: CVE-2022-30045 incorrect memory handling leading to a heap out-of-bounds read Package: src:mapcache; Maintainer for src:mapcache is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Neil Williams <codehelp@debianorg> Date: Tue, 5 Jul 2022 09:18:02 ...
An issue was discovered in libezxmla in ezXML 086 The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read ...