The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade libxml2 | Jul 14, 2016 | May 17, 2016 |
| Centos_linux | — | Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-staticUpgrade libxml2-python | Jul 22, 2016 | May 17, 2016 |
| Debian | — | Upgrade libxml2 | Jun 3, 2016 | May 17, 2016 |
| F5 Big Ip | — | — | Feb 16, 2017 | May 17, 2016 |
| Freebsd | — | Upgrade libxml2 | Dec 10, 2025 | Aug 28, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | May 17, 2016 |
| Oracle Solaris | — | Upgrade library/python/libxsl-26 to version 1.1.28-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/python/libxml2-26 to version 2.9.4-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/libxml2 to version 2.9.4-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/python/libxml2-27 to version 2.9.4-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.4-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/python/libxsl-27 to version 1.1.28-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/libxslt to version 1.1.28-0.175.3.11.0.4.0 on Solaris 11.3 | May 29, 2017 | May 17, 2016 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2 | Jun 23, 2016 | May 17, 2016 |
| Redhat_linux | — | Upgrade libxml2No solution existsUpgrade libxml2-staticUpgrade libxml2-pythonUpgrade libxml2-debuginfoUpgrade libxml2-devel | Jul 29, 2016 | May 17, 2016 |
| Suse | — | Upgrade libxml2-32bitUpgrade libxml2-devel-32bitUpgrade sles12sp1-docker-imageUpgrade libxml2-x86Upgrade python3-libxml2-pythonUpgrade python-libxml2Upgrade libxml2-pythonUpgrade libxml2-2Upgrade python2-libxml2-pythonUpgrade sles12-docker-imageUpgrade libxml2-2-32bitUpgrade libxml2-toolsUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-doc | May 3, 2016 | May 3, 2016 |
| Ubuntu | — | Upgrade libxml2 | Jun 6, 2016 | May 17, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub