Fedora 37 : vtk (2023-2cf9dd7d52)
Discription
The remote Fedora 37 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2023-2cf9dd7d52 advisory.
– There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn’t check the return value of libxml2 API ‘xmlDocGetRootElement’, and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application. (CVE-2021-42521)
Note that Nessus has not tested for this issue but has instead relied only on the application’s self-reported version number.Read More
References
Back to Main