PT-2016-3269 · Libxml2+5 · Libxml2+5

Published

2016-03-12

·

Updated

2024-06-15

·

CVE-2016-3627

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.9.3 and earlier
Description The issue is related to the xmlStringGetNodeList function in tree.c of the libxml2 library. It is caused by uncontrolled recursion when the function is used in recovery mode. This allows attackers to cause a denial of service, including infinite recursion, stack consumption, and application crash, by using a specially crafted XML document. There is no information about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For libxml2 versions 2.9.3 and earlier, as a temporary workaround, consider disabling the xmlStringGetNodeList function when used in recovery mode until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1221
ALT-PU-2017-1240
BDU:2018-01271
CESA-2016_1292
CVE-2016-3627
DLA-503-1
DSA-3593-1
MGASA-2016-0187
OPENSUSE-SU-2016_1594-1
OPENSUSE-SU-2024:10192-1
OPENSUSE-SU-2024:10228-1
RHSA-2016:1292
RHSA-2016_1292
SUSE-SU-2016:1204-1
SUSE-SU-2016:1205-1
SUSE-SU-2016_1204-1
SUSE-SU-2016_1205-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2994-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2