libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Oct 19, 2018 | Oct 18, 2018 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest versionApply OS X security update 2017-001 Sierra | Oct 19, 2018 | May 18, 2017 |
| Debian | — | Upgrade libxml2 | Aug 23, 2017 | May 18, 2017 |
| Freebsd | — | Upgrade libxml2 | Dec 14, 2017 | Dec 13, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | May 18, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-python | Nov 19, 2019 | May 18, 2017 |
| Oracle Solaris | — | Upgrade library/libxml2 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-27 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3 | Jan 19, 2021 | May 18, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2017 |
| Suse | — | Upgrade libxml2-docUpgrade libxml2-2-32bitUpgrade libxml2-pythonUpgrade libxml2-x86Upgrade sles12sp1-docker-imageUpgrade libxml2-toolsUpgrade sles12-docker-imageUpgrade libxml2-32bitUpgrade libxml2Upgrade python-libxml2Upgrade libxml2-devel-32bitUpgrade libxml2-2Upgrade libxml2-develUpgrade sles12sp2-docker-image | May 31, 2017 | May 18, 2017 |
| Ubuntu | — | Upgrade libxml2 | Sep 19, 2017 | May 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub