xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2Upgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2-staticUpgrade libxml2-python | Apr 27, 2020 | Sep 25, 2016 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest version | Nov 11, 2016 | Sep 25, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 25, 2016 |
| Centos_linux | — | Upgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-staticUpgrade libxml2-python | Oct 14, 2021 | Sep 25, 2016 |
| Debian | — | Upgrade libxml2 | Dec 24, 2016 | Sep 25, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Sep 25, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2 | Sep 12, 2019 | Sep 25, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Sep 25, 2019 | Sep 25, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Jul 2, 2019 | Sep 25, 2016 |
| Oracle_linux | — | Upgrade libxml2-develUpgrade libxml2-staticUpgrade libxml2-pythonUpgrade libxml2 | Oct 13, 2021 | Oct 12, 2016 |
| Redhat_linux | — | Upgrade libxml2Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-debuginfoNo solution exists | Oct 14, 2021 | Sep 25, 2016 |
| Suse | — | Upgrade sles12-docker-imageUpgrade sles12sp1-docker-imageUpgrade python3-libxml2-pythonUpgrade libxml2-2Upgrade libxml2Upgrade ruby2.5-rubygem-nokogiriUpgrade libxml2-devel-32bitUpgrade libxml2-x86Upgrade libxml2-toolsUpgrade sles12sp2-docker-imageUpgrade libxml2-develUpgrade python-libxml2Upgrade libxml2-docUpgrade python2-libxml2-pythonUpgrade libxml2-2-32bitUpgrade libxml2-pythonUpgrade libxml2-32bit | Oct 26, 2016 | Sep 25, 2016 |
| Ubuntu | — | Upgrade libxml2 | Mar 18, 2017 | Sep 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub