libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Oct 19, 2018 | May 18, 2017 |
| Apple Osx Libxml2 | — | Apply OS X security update 2017-001 SierraUpgrade macOS to the latest version | Oct 19, 2018 | May 18, 2017 |
| Debian | — | Upgrade libxml2 | Aug 23, 2017 | May 18, 2017 |
| Freebsd | — | Upgrade libxml2 | Dec 14, 2017 | Dec 13, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | May 18, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2 | Nov 19, 2019 | May 18, 2017 |
| Oracle Solaris | — | Upgrade library/libxml2 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-27 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3 | Jan 19, 2021 | May 18, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2017 |
| Suse | — | Upgrade libxml2-2Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-devel-32bitUpgrade python-libxml2Upgrade sles12sp2-docker-imageUpgrade libxml2-32bitUpgrade sles12sp1-docker-imageUpgrade libxml2-2-32bitUpgrade libxml2-toolsUpgrade libxml2-docUpgrade libxml2-x86Upgrade sles12-docker-imageUpgrade libxml2-python | May 31, 2017 | May 18, 2017 |
| Ubuntu | — | Upgrade libxml2 | Sep 19, 2017 | May 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub