5
CVSSv2

CVE-2017-16932

Published: 23/11/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

parser.c in libxml2 prior to 2.9.5 does not prevent infinite recursion in parameter entities.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2

Vendor Advisories

Debian Bug report logs - #882613 libxml2: CVE-2017-16932: Infinite recursion in parameter entities Package: src:libxml2; Maintainer for src:libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 24 Nov 2017 19:42:01 UTC Severit ...
curl could be made to crash if it received specially crafted input ...
libxml2 could be made to crash if it opened a specially crafted file ...
Several security issues were fixed in libxml2 ...
parserc in libxml2 before 295 does not prevent infinite recursion in parameter entities ...