Описание
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.9.4+dfsg1-2.2 |
| esm-infra-legacy/trusty | released | 2.9.1+dfsg1-3ubuntu4.9 |
| esm-infra/xenial | released | 2.9.3+dfsg1-1ubuntu0.2 |
| precise | released | 2.7.8.dfsg-5.1ubuntu4.17 |
| precise/esm | not-affected | 2.7.8.dfsg-5.1ubuntu4.17 |
| trusty | released | 2.9.1+dfsg1-3ubuntu4.9 |
| trusty/esm | released | 2.9.1+dfsg1-3ubuntu4.9 |
| upstream | released | 2.9.5 |
| vivid/stable-phone-overlay | ignored | end of life |
| vivid/ubuntu-core | DNE |
Показывать по
Ссылки на источники
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS ...
EPSS
10 Critical
CVSS2
9.8 Critical
CVSS3