libxmljs2@0.21.4 vulnerabilities

libxml bindings for v8 javascript engine

Direct Vulnerabilities

Known vulnerabilities in the libxmljs2 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Type Confusion

libxmljs2 is a libxml bindings for v8 javascript engine

Affected versions of this package are vulnerable to Type Confusion when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity.

Exploiting this vulnerability leads to an RCE, data leak DoS on 64-bit and 32-bit systems.

How to fix Type Confusion?

There is no fixed version for libxmljs2.

*
  • H
Type Confusion

libxmljs2 is a libxml bindings for v8 javascript engine

Affected versions of this package are vulnerable to Type Confusion due to the improper handling of a specially crafted XML file. An attacker can cause a denial of service, data leak, infinite loop, or execute arbitrary code by invoking a function on the result of attrs() that was called on a parsed node.

How to fix Type Confusion?

There is no fixed version for libxmljs2.

*