The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | apple-itunes-upgrade-latest | Dec 16, 2016 | Dec 16, 2016 | |
| Apple Osx Libxml2 | apple-osx-security-update-2016-004apple-osx-upgrade-latest | Nov 11, 2016 | Nov 11, 2016 | |
| Debian | debian-upgrade-libxml2 | Jun 3, 2016 | Jun 2, 2016 | |
| Freebsd | freebsd-upgrade-package-libxml2 | Dec 10, 2025 | Aug 28, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-libxml2 | Oct 30, 2017 | Apr 11, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libxml2huawei-euleros-2_0_sp2-upgrade-libxml2-develhuawei-euleros-2_0_sp2-upgrade-libxml2-python | Sep 12, 2019 | Apr 11, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libxml2huawei-euleros-2_0_sp3-upgrade-libxml2-develhuawei-euleros-2_0_sp3-upgrade-libxml2-python | Sep 25, 2019 | Apr 11, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libxml2huawei-euleros-2_0_sp5-upgrade-libxml2-develhuawei-euleros-2_0_sp5-upgrade-libxml2-python | Aug 16, 2019 | Apr 11, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-library-libxml2-2-9-4-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-libxslt-1-1-28-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-python-libxml2-26-2-9-4-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-python-libxml2-27-2-9-4-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-python-libxml2-34-2-9-4-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-python-libxsl-26-1-1-28-0-175-3-11-0-4-0oracle-solaris-11-3-upgrade-library-python-libxsl-27-1-1-28-0-175-3-11-0-4-0 | May 29, 2017 | Apr 11, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | May 3, 2016 | |
| Suse | — | suse-upgrade-libxml2suse-upgrade-libxml2-2suse-upgrade-libxml2-2-32bitsuse-upgrade-libxml2-32bitsuse-upgrade-libxml2-develsuse-upgrade-libxml2-devel-32bitsuse-upgrade-libxml2-docsuse-upgrade-libxml2-pythonsuse-upgrade-libxml2-toolssuse-upgrade-libxml2-x86suse-upgrade-python-libxml2suse-upgrade-python2-libxml2-pythonsuse-upgrade-python3-libxml2-pythonsuse-upgrade-sles12-docker-imagesuse-upgrade-sles12sp1-docker-image | Jun 9, 2016 | Jun 2, 2016 |
| Ubuntu | ubuntu-upgrade-libxml2 | Jun 6, 2016 | Jun 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub