ZeroHour

CVE-2016-3627

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.

Vendors
opensusedebianhpxmlsoftcanonicalredhatoracle
Products
leap, debian linux, icewall federation agent, icewall file manager, libxml2, ubuntu linux, jboss core services, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux workstation
Weakness
CWE-674
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.