vulnerability
SUSE: CVE-2016-4447: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Jun 9, 2016 | Jun 9, 2016 | Feb 4, 2022 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jun 9, 2016
Added
Jun 9, 2016
Modified
Feb 4, 2022
Description
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
Solution(s)
suse-upgrade-libxml2suse-upgrade-libxml2-2suse-upgrade-libxml2-2-32bitsuse-upgrade-libxml2-32bitsuse-upgrade-libxml2-develsuse-upgrade-libxml2-devel-32bitsuse-upgrade-libxml2-docsuse-upgrade-libxml2-pythonsuse-upgrade-libxml2-toolssuse-upgrade-libxml2-x86suse-upgrade-python-libxml2suse-upgrade-sles12-docker-imagesuse-upgrade-sles12sp1-docker-image
References
- SUSE-SUSE-SU-2016:1538-1
- SUSE-SUSE-SU-2016:1604-1
- SUSE-SUSE-SU-2017:2699-1
- SUSE-SUSE-SU-2017:2700-1
- APPLE-APPLE-SA-2016-07-18-1
- APPLE-APPLE-SA-2016-07-18-2
- APPLE-APPLE-SA-2016-07-18-3
- APPLE-APPLE-SA-2016-07-18-6
- REDHAT-RHSA-2016:1292
- REDHAT-RHSA-2016:2957
- BID-90864
- SECTRACK-1036348
- UBUNTU-USN-2994-1
- DEBIAN-DLA-503-1
- DEBIAN-DSA-3593
- NVD-CVE-2016-4447

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.