Junglewise Threat Intelligence

CVE-2024-34394: libxmljs2 type confusion in XML parsing

CVE-2024-34394 · Severity: low · CVSS 3.1 · Published 2024-05-02

Vendors: npm.

Executive brief

libxmljs2 is a JavaScript library for parsing and manipulating XML documents. A type confusion vulnerability in the library's namespace handling can be exploited by parsing specially crafted XML files, potentially allowing attackers to crash the application or execute arbitrary code on systems using affected versions.

Technical details

libxmljs2 is vulnerable to a type confusion vulnerability (CWE-843) triggered when parsing specially crafted XML documents and invoking the namespaces() function on a grand-child of a node that refers to an entity. The root cause lies in improper type handling within the XmlNode::get_local_namespaces() method. The vulnerability requires network-reachable parsing of attacker-controlled XML input with no authentication or user interaction required. Successful exploitation can lead to denial of service or remote code execution on the affected system. Patches addressing this vulnerability are expected to be available in versions following 0.35.0.

Affected products

  • libxmljs2 libxmljs2 up to 0.35.0

Timeline

  • 2024-05-02: disclosed
  • 2024-05-03: advisory: GitHub security advisory reviewed

References

Related threats