Severity
5.5MEDIUM
EPSS
1.2%
top 20.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 14

Description

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

NVDapple/tvos< 9.2.1
NVDapple/watchos< 2.2.1
NVDapple/mac_os_x< 10.11.5
NVDapple/iphone_os< 9.3.2
NVDxmlsoft/libxml2< 2.9.4

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Enterprise Linux 7.2, 7.3, 7.4, 7.6, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m2m4-q8jw-j56w: The htmlCurrentChar function in libxml2 before 22022-05-14
CVEList
CVE-2016-1833: The htmlCurrentChar function in libxml2 before 22016-05-20
OSV
CVE-2016-1833: The htmlCurrentChar function in libxml2 before 22016-05-20

📋Vendor Advisories

7
Ubuntu
libxml2 vulnerabilities2016-06-06
Debian
CVE-2016-1833: libxml2 - The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS befor...2016
Red Hat
libxml2: Heap-based buffer overread in htmlCurrentChar2015-11-27
Apple
CVE-2016-1833: tvOS 9.2.1
Apple
CVE-2016-1833: OS X El Capitan v10.11.5 and Security Update 2016-003

💬Community

4
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-a2016-06-24
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fe2016-06-24
Bugzilla
CVE-2016-1833 libxml2: Heap-based buffer overread in htmlCurrentChar2016-05-23
Bugzilla
CVE-2016-3107 pulp: Node certificate containing private key stored in world-readable file2016-04-11
CVE-2016-1833 (MEDIUM CVSS 5.5) | The htmlCurrentChar function in lib | cvebase.io