xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
Critical severity
GitHub Reviewed
Published
Oct 7, 2022
to the GitHub Advisory Database
•
Updated May 30, 2024
Description
Published by the National Vulnerability Database
Sep 16, 2020
Published to the GitHub Advisory Database
Oct 7, 2022
Reviewed
Oct 7, 2022
Last updated
May 30, 2024
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
References