PT-2017-4234 · Xmlsoft+4 · Libxml2+4

Published

2017-03-03

·

Updated

2026-02-06

·

CVE-2017-16932

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.5
Description The issue is related to infinite recursion in parameter entities, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 2.9.5, update to version 2.9.5 or later to resolve the issue.

Exploit

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1240
BDU:2023-00219
CLEANSTART-2026-LA13761
CLEANSTART-2026-NJ87139
CLEANSTART-2026-TC95380
CLEANSTART-2026-WX01708
CVE-2017-16932
DLA-1194-1
DLA-2972-1
GHSA-X2FM-93WW-GGVX
MGASA-2018-0048
MGASA-2018-0050
SUSE-SU-2018:0395-1
SUSE-SU-2022:1833-1
SUSE-SU-2022_1833-1
USN-3504-1
USN-3504-2
USN-3739-1

Affected Products

Alt Linux
Astra Linux
Suse
Ubuntu
Libxml2