parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxml2 | Jan 26, 2018 | Nov 23, 2017 |
| Amazon Linux Ami 2 | — | Upgrade libxml2Upgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2-static | Apr 27, 2020 | Nov 23, 2017 |
| Amazon_linux | — | Upgrade libxml2 | May 4, 2023 | Nov 23, 2017 |
| Debian | — | Upgrade libxml2 | Feb 25, 2019 | Nov 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | May 2, 2018 | Nov 23, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-python | May 2, 2018 | Nov 23, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-python | Jun 28, 2018 | Nov 23, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 5, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub