QID 330144

Date Published: 2023-08-02

QID 330144: IBM AIX Denial of Service (DoS) Vulnerability in libxml2 (libxml2_advisory5)

Vulnerabilities in libxml2 could allow a remote attacker to cause a denial of service

Affected Platform:
AIX 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i bos.rte.control It also checks for interim fixes installed using the command " emgr -c; or instfix -k. The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

Successful exploit may impact availability

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The vendor has released fixes to AIX advisory this vulnerability.

    CVEs related to QID 330144

    Software Advisories
    Advisory ID Software Component Link
    libxml2_advisory5 URL Logo aix.software.ibm.com/aix/efixes/security/libxml2_advisory5.asc