{"id":137924,"date":"2025-06-21T23:12:01","date_gmt":"2025-06-21T21:12:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda"},"modified":"2025-06-21T23:12:01","modified_gmt":"2025-06-21T21:12:01","slug":"uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda","title":{"rendered":"Vuln\u00e9rabilit\u00e9s dans la biblioth\u00e8que libxml2, pouvant potentiellement conduire \u00e0 l'ex\u00e9cution de code","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans la biblioth\u00e8que Libxml2, d\u00e9velopp\u00e9e par le projet GNOME et utilis\u00e9e pour analyser le contenu au format XML, cinq vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 identifi\u00e9es, dont deux pourraient potentiellement entra\u00eener l'ex\u00e9cution de code lors du traitement de donn\u00e9es externes sp\u00e9cialement con\u00e7ues. La biblioth\u00e8que Libxml2 est largement r\u00e9pandue dans les projets open source et, par exemple, est utilis\u00e9e comme d\u00e9pendance dans plus de 800 paquets de la distribution Ubuntu.    <\/p>\n<p>La premi\u00e8re vuln\u00e9rabilit\u00e9 (CVE-2025-6170) est caus\u00e9e par un d\u00e9bordement de tampon dans la mise en \u0153uvre de l'outil en ligne de commande xmllint, utilis\u00e9 pour analyser des fichiers XML. Le d\u00e9bordement se produit lors du traitement d'arguments de commande tr\u00e8s longs en raison de l'absence de v\u00e9rification ad\u00e9quate de la taille des donn\u00e9es d'entr\u00e9e avant la copie des donn\u00e9es par la fonction strcpy(). Pour exploiter la vuln\u00e9rabilit\u00e9, un attaquant doit \u00eatre en mesure d'influencer les commandes transmises \u00e0 l'outil xmllint. Un correctif pour rem\u00e9dier \u00e0 cette vuln\u00e9rabilit\u00e9 n'est pas encore disponible.    <\/p>\n<p>La deuxi\u00e8me vuln\u00e9rabilit\u00e9 (CVE-2025-6021) est pr\u00e9sente dans l'impl\u00e9mentation de la fonction xmlBuildQName() et conduit \u00e0 l'\u00e9criture de donn\u00e9es en dehors du tampon en raison d'un d\u00e9bordement d'entier lors du calcul de la taille du tampon bas\u00e9 sur le pr\u00e9fixe et le nom local. Pour exploiter la vuln\u00e9rabilit\u00e9, un attaquant doit \u00eatre en mesure d'injecter ses propres donn\u00e9es dans les arguments prefix et ncname pass\u00e9s \u00e0 la fonction xmlBuildQName(). Un correctif a \u00e9t\u00e9 pr\u00e9par\u00e9 pour rem\u00e9dier \u00e0 cette vuln\u00e9rabilit\u00e9. La correction est incluse dans la version libxml2 2.14.4. Pour v\u00e9rifier l'\u00e9tat de la nouvelle version du paquet ou la pr\u00e9paration du correctif dans les distributions, vous pouvez consulter les pages suivantes (si la page est inaccessible, cela signifie que les d\u00e9veloppeurs de la distribution n'ont pas encore commenc\u00e9 \u00e0 traiter le probl\u00e8me) : Debian, Ubuntu, Fedora, SUSE\/openSUSE, RHEL, Gentoo et Arch (1, 2).     <\/p>\n<p>Les trois autres probl\u00e8mes entra\u00eenent un crash en raison de l'acc\u00e8s \u00e0 une zone m\u00e9moire d\u00e9j\u00e0 lib\u00e9r\u00e9e dans la fonction xmlSchematronGetNode (CVE-2025-49794), d'un d\u00e9r\u00e9f\u00e9rencement de pointeur nul dans la fonction xmlXPathCompiledEval (CVE-2025-49795) et d'un traitement incorrect des types (Type Confusion) dans la fonction xmlSchematronFormatReport (CVE-2025-49796). Pour rem\u00e9dier \u00e0 ces vuln\u00e9rabilit\u00e9s, il est envisag\u00e9 de supprimer le support du langage de balisage Schematron dans libxml2.         <\/p>\n<p>Il est \u00e9galement \u00e0 noter la pr\u00e9sence de trois vuln\u00e9rabilit\u00e9s non corrig\u00e9es dans la biblioth\u00e8que libxslt, qui n'est plus maintenue. Les informations concernant ces probl\u00e8mes ne sont pas encore divulgu\u00e9es et seront publi\u00e9es les 9 juillet, 13 juillet et 6 ao\u00fbt. Des vuln\u00e9rabilit\u00e9s non corrig\u00e9es et non divulgu\u00e9es au public sont \u00e9galement signal\u00e9es dans les projets li\u00e9s \u00e0 GNOME tels que gvfs, libgxps, gdm, glib, GIMP et libsoup.        <\/p>\n<p>Compl\u00e9ment : Le mainteneur de libxml2 a annonc\u00e9 qu'il consid\u00e9rera d\u00e9sormais les vuln\u00e9rabilit\u00e9s comme des erreurs ordinaires, sans les prioriser davantage, les corrigeant lorsqu'il en aura le temps et divulguant imm\u00e9diatement des informations sur la nature de la vuln\u00e9rabilit\u00e9 sans imposer d'embargo ni accorder de temps pour la rem\u00e9dier dans des produits tiers.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63431\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Libxml2, \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c GNOME \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 XML, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0432\u043d\u0435\u0448\u043d\u0438\u0445 \u0434\u0430\u043d\u043d\u044b\u0445. \u0411\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430 Libxml2 \u0448\u0438\u0440\u043e\u043a\u043e \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 \u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043a\u0430\u043a \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0431\u043e\u043b\u0435\u0435 \u0447\u0435\u043c 800 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Ubuntu. \u041f\u0435\u0440\u0432\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-6170) [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-137924","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Libxml2, \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c GNOME \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 XML, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libxml2, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0438\u0435 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Libxml2, \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c GNOME \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 XML, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-06-21T21:12:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-06-21T21:12:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9s dans la biblioth\u00e8que libxml2, pouvant potentiellement permettre l'ex\u00e9cution de code | ProHoster","description":"Cinq vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 identifi\u00e9es dans la biblioth\u00e8que Libxml2, d\u00e9velopp\u00e9e par le projet GNOME et utilis\u00e9e pour analyser le contenu au format XML, dont deux pourraient potentiellement permettre l'ex\u00e9cution de code lors du traitement de cas sp\u00e9cifiques.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libxml2, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0438\u0435 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster","og:description":"\u0412 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Libxml2, \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c GNOME \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 XML, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-biblioteke-libxml2-potenczialno-privodyashhie-k-vypolneniyu-koda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-06-21T21:12:01+00:00","article:modified_time":"2025-06-21T21:12:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"137924","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 13:23:11","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 13:23:11","updated":"2026-01-23 13:23:11","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/137924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=137924"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/137924\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=137924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=137924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=137924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}