PT-2016-3272 · Libxml2+5 · Libxml2+5

Liu Yang

+1

·

Published

2016-03-12

·

Updated

2023-02-12

·

CVE-2016-4447

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.4
Description The issue is related to the xmlParseElementDecl function in parser.c, which allows context-dependent attackers to cause a denial of service. This can be achieved through a crafted file, involving xmlParseName, and may result in a heap-based buffer underread and application crash. The vulnerability is also associated with a buffer overflow in memory.
Recommendations For versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xmlParseElementDecl function until a patch is available. Avoid using the xmlParseName function in conjunction with xmlParseElementDecl until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1221
BDU:2018-01274
CESA-2016_1292
CVE-2016-4447
DLA-503-1
DSA-3593-1
MGASA-2016-0263
OPENSUSE-SU-2016_1595-1
RHSA-2016:1292
RHSA-2016_1292
SUSE-SU-2016:1538-1
SUSE-SU-2016:1604-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2994-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2