Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5969

Опубликовано: 11 апр. 2017
Источник: debian
EPSS Низкий

Описание

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.9.4+dfsg1-5.1package
libxml2no-dsajessiepackage
libxml2no-dsawheezypackage

Примечания

  • https://www.openwall.com/lists/oss-security/2016/11/05/3

  • Upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=778519

  • Duplicate upstream bug (contains patch): https://bugzilla.gnome.org/show_bug.cgi?id=758422

  • Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/94691dc884d1a8ada39f073408b4bb92fe7fe882

EPSS

Процентиль: 86%
0.02935
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 5.5
redhat
больше 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 4.7
nvd
почти 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 4.7
github
больше 3 лет назад

** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."

CVSS3: 5.3
fstec
почти 9 лет назад

Уязвимость библиотеки Libxml2, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.02935
Низкий