PT-2016-1545 · Xmlsoft+5 · Libxml2+5

Puzzor

·

Published

2016-03-23

·

Updated

2025-12-17

·

CVE-2016-1762

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.4
Description The issue is related to a heap-based buffer over-read in the xmlNextChar function, allowing remote attackers to cause a denial of service. It may also lead to arbitrary code execution or memory damage through a specially crafted XML document.
Recommendations For versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xmlNextChar function until a patch is available. Avoid processing untrusted XML documents with the affected libxml2 versions to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1240
BDU:2016-00846
CESA-2016_1292
CVE-2016-1762
DLA-503-1
DSA-3593-1
MGASA-2016-0263
OPENSUSE-SU-2016_1594-1
OPENSUSE-SU-2016_1595-1
OPENSUSE-SU-2024:10192-1
OPENSUSE-SU-2024:10228-1
RHSA-2016:1292
RHSA-2016_1292
SUSE-SU-2016:1538-1
SUSE-SU-2016:1604-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2994-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2