CVE-2016-3705
published 2016-05-17CVE-2016-3705: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.10%
91.4th percentile
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1.1 (bookworm) | libxml2 2.9.3+dfsg1-1.1 (bookworm) |
| debian | libxml2 | — | — |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| opensuse | leap | — | — |
| red_hat | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1.1 | 2.9.3+dfsg1-1.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1.1 | 2.9.3+dfsg1-1.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1.1 | 2.9.3+dfsg1-1.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1.1 | 2.9.3+dfsg1-1.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.8 | 2.9.1+dfsg1-3ubuntu4.8 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.1 | 2.9.3+dfsg1-1ubuntu0.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6qj-ff26-p4v7: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser
ghsa_unreviewed·2022-05-14
CVE-2016-3705 [HIGH] CWE-20 GHSA-r6qj-ff26-p4v7: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
GHSA
GHSA-94gc-v83r-7m7w: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2016-9597 [HIGH] CWE-119 GHSA-94gc-v83r-7m7w: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
OSV
libxml2 vulnerabilities
osv·2016-06-06·CVSS 7.5
CVE-2015-8806 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2015-8806, CVE-2016-2073,
CVE-2016-3627, CVE-2016-3705, CVE-2016-4447)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-1762, CVE-2016-1834)
Mateusz Jurczyk discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
OSV
CVE-2016-3705: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser
osv·2016-05-17·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2016-06-06·CVSS 7.5
CVE-2015-8806 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2015-8806, CVE-2016-2073,
CVE-2016-3627, CVE-2016-3705, CVE-2016-4447)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-1762, CVE-2016-1834)
Mateusz Jurczyk discovered that libxml2 incorrectly handled certain
malfo
Red Hat
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
vendor_redhat·2016-05-03·CVSS 7.5
CVE-2016-9597 [HIGH] CWE-674 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 6) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat JBoss Core Services) - Affected
Red Hat
libxml2: stack overflow before detecting invalid XML file
vendor_redhat·2016-05-03·CVSS 7.5
CVE-2016-3705 [HIGH] CWE-674 libxml2: stack overflow before detecting invalid XML file
libxml2: stack overflow before detecting invalid XML file
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Missing incrementation of recursion depth counter were found in the xmlParserEntityCheck() and xmlParseAttValueComplex() functions used for parsing XML data. An attacker could launch a Denial of Service attack by passing specially crafted XML data to an application, forcing it to crash due to stack exhaustion.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: httpd (Red
Debian
CVE-2016-9597: libxml2 - It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-201...
vendor_debian·2016·CVSS 7.5
CVE-2016-9597 [HIGH] CVE-2016-9597: libxml2 - It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-201...
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2016-3705: libxml2 - The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser...
vendor_debian·2016·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705: libxml2 - The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser...
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1.1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1.1)
forky: resolved (fixed in 2.9.3+dfsg1-1.1)
sid: resolved (fixed in 2.9.3+dfsg1-1.1)
trixie: resolved (fixed in 2.9.3+dfsg1-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9597 [HIGH] CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
It was found that Red Hat JBoss Core Services incorrectly included CVE-2016-3705 as resolved in Apache HTTP 2.4.23 (erratum RHSA-2016:2957). The release did not include the fix to libxml2, leaving it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for CVE-2016-3705.
Discussion:
Are there any details available for this? Upsteam bug, commit reference?
---
(In reply to Salvatore Bonaccorso from comment #2)
> Are there any details available for this? Upsteam bug, commit reference?
Referring to https://bugzilla.redhat.com/show_bug.cgi?id=1408302#c4
---
Hi Adam
Thanks for the information here and in the related bugs. I guess there is though s
Bugzilla
CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [fedora-all]
bugzilla·2016-05-04·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [fedora-all]
CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file [fedora-all]
bugzilla·2016-05-04·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file [fedora-all]
CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [epel-7]
bugzilla·2016-05-04·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [epel-7]
CVE-2016-3705 mingw-libxml2: libxml2: stack overflow before detecting invalid XML file [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: ad
Bugzilla
CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file
bugzilla·2016-05-03·CVSS 7.5
CVE-2016-3705 [HIGH] CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file
CVE-2016-3705 libxml2: stack overflow before detecting invalid XML file
It is possible to trigger a stack overflow using a carefully crafted invalid xml file, the stack overflow occurs before libxml2 determines the xml file is invalid.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=765207
Discussion:
Created attachment 1153279
proposed patch
---
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1332831]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1332832]
Affects: epel-7 [bug 1332833]
---
Public via:
http://seclists.org/fulldisclosure/2016/May/10
---
Upstream commit for this issue :
https://git.gnome.org/browse/libxml2/commit/?h=CVE-2016-3705&id=8f30bdff69edac9075f4663ce3b56b0c52d48ce6
---
This issue has
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-01-31
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-updates/2016-05/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00127.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://seclists.org/fulldisclosure/2016/May/10http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/89854http://www.ubuntu.com/usn/USN-2994-1https://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.gnome.org/show_bug.cgi?id=765207https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157239https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://security.gentoo.org/glsa/201701-37https://www.debian.org/security/2016/dsa-3593https://www.tenable.com/security/tns-2016-18http://lists.opensuse.org/opensuse-updates/2016-05/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00127.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://seclists.org/fulldisclosure/2016/May/10http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/89854http://www.ubuntu.com/usn/USN-2994-1https://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.gnome.org/show_bug.cgi?id=765207https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157239https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://security.gentoo.org/glsa/201701-37https://www.debian.org/security/2016/dsa-3593https://www.tenable.com/security/tns-2016-18
2016-05-17
Published