libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
CVSS Details
- CVSS 3.0 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxml2 | Aug 30, 2017 | Apr 11, 2017 |
| Apple Osx Libxml2 | — | Apply OS X security update 2017-004 El CapitanApply OS X security update 2017-001 Sierra | Oct 19, 2018 | Apr 11, 2017 |
| Debian | — | Upgrade libxml2 | Apr 11, 2022 | Apr 11, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | Apr 11, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Dec 4, 2019 | Apr 11, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libxml2Upgrade libxml2-pythonUpgrade libxml2-devel | Dec 18, 2019 | Apr 11, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-python | Nov 19, 2019 | Apr 11, 2017 |
| Oracle Solaris | — | Upgrade library/python/libxml2-27 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/libxml2 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3 | Dec 19, 2017 | Apr 11, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 5, 2016 |
| Suse | — | Upgrade python-libxml2Upgrade libxml2-32bitUpgrade libxml2-2-32bitUpgrade python2-libxml2-pythonUpgrade libxml2-docUpgrade libxml2-2Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2Upgrade sles12sp2-docker-imageUpgrade python3-libxml2-pythonUpgrade libxml2-toolsUpgrade libxml2-devel-32bitUpgrade libxml2-x86 | Jun 26, 2017 | Apr 11, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub