CVE-2017-16932

Name
CVE-2017-16932
Description
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes http://xmlsoft.org/news.html
cve@mitre.org https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html
Permissions Required https://bugzilla.gnome.org/show_bug.cgi?id=759579
Patch https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
cve@mitre.org https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
cve@mitre.org https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
cve@mitre.org https://usn.ubuntu.com/3739-1/
cve@mitre.org https://gitlab.gnome.org/GNOME/libxml2/-/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
cve@mitre.org https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* libxml2 >= None <= 2.9.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxml2 edge-main 2.9.4-r4 None possibly vulnerable
libxml2 edge-main 2.9.4-r2 None possibly vulnerable
libxml2 edge-main 2.9.4-r1 None possibly vulnerable
libxml2 3.22-main 2.9.4-r4 None possibly vulnerable
libxml2 3.22-main 2.9.4-r2 None possibly vulnerable
libxml2 3.22-main 2.9.4-r1 None possibly vulnerable
libxml2 3.21-main 2.9.4-r4 None possibly vulnerable
libxml2 3.21-main 2.9.4-r2 None possibly vulnerable
libxml2 3.21-main 2.9.4-r1 None possibly vulnerable
libxml2 3.20-main 2.9.4-r4 None possibly vulnerable
libxml2 3.20-main 2.9.4-r2 None possibly vulnerable
libxml2 3.20-main 2.9.4-r1 None possibly vulnerable
libxml2 3.19-main 2.9.4-r4 None possibly vulnerable
libxml2 3.19-main 2.9.4-r2 None possibly vulnerable
libxml2 3.19-main 2.9.4-r1 None possibly vulnerable
clamav edge-community 0.100.1-r0 None fixed
clamav 3.22-community 0.100.1-r0 None fixed
clamav 3.21-community 0.100.1-r0 None fixed
clamav 3.20-community 0.100.1-r0 None fixed
clamav 3.19-community 0.100.1-r0 None fixed
clamav 3.18-community 0.100.1-r0 None fixed
clamav 3.17-community 0.100.1-r0 None fixed
clamav 3.12-main 0.100.1-r0 None fixed
clamav 3.11-main 0.100.1-r0 None fixed
clamav 3.10-main 0.100.1-r0 None fixed