CVE-2016-4448
published 2016-06-09CVE-2016-4448: Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.04%
93.5th percentile
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 5.2.1 | 5.2.1 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.2 | — |
| apple | itunes | <= 12.4.1 | — |
| apple | itunes_12.4.2_for_windows | — | — |
| apple | mac_os_x | < 10.11.6 | 10.11.6 |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| apple | tvos | <= 9.2.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.2.1 | — |
| apple | watchos | — | — |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-1 (bookworm) | libxml2 2.9.4+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| mcafee | web_gateway | <= 7.5.2.10 | — |
| mcafee | web_gateway | 7.6.0.0 – 7.6.2.3 | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wfj9-g4pj-c38g: Format string vulnerability in libxml2 before 2
ghsa_unreviewed·2022-05-13
CVE-2016-4448 [CRITICAL] CWE-134 GHSA-wfj9-g4pj-c38g: Format string vulnerability in libxml2 before 2
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
OSV
libxml2 vulnerabilities
osv·2017-03-16·CVSS 9.8
CVE-2016-4448 [CRITICAL] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled format strings. If a
user or automated system were tricked into opening a specially crafted
document, an attacker could possibly cause libxml2 to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04
LTS, and Ubuntu 16.04 LTS. (CVE-2016-4448)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-4658)
Nick Wellnhofer discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
openi
OSV
CVE-2016-4448: Format string vulnerability in libxml2 before 2
osv·2016-06-09·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: Format string vulnerability in libxml2 before 2
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2017-03-16·CVSS 9.8
CVE-2016-4448 [CRITICAL] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled format strings. If a
user or automated system were tricked into opening a specially crafted
document, an attacker could possibly cause libxml2 to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04
LTS, and Ubuntu 16.04 LTS. (CVE-2016-4448)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-4658)
Nick Wellnhofer discovered that libxml2 incorrectly handled certain
malformed
Apple
CVE-2016-4448: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4448
Component: LibreSSL
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple issues existed in LibreSSL before 2.2.7. These were addressed by updating LibreSSL to version 2.2.7.
Apple
CVE-2016-4448: iTunes 12.4.2 for Windows
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: iTunes 12.4.2 for Windows
Apple Security Update: About the security content of iTunes 12.4.2 for Windows
Product: iTunes 12.4.2 for Windows
CVE: CVE-2016-4448
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2016-4448: iCloud for Windows 5.2.1
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: iCloud for Windows 5.2.1
Apple Security Update: About the security content of iCloud for Windows 5.2.1
Product: iCloud for Windows
Version: 5.2.1
CVE: CVE-2016-4448
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2016-4448: watchOS 2.2.2
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2016-4448
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
Apple
CVE-2016-4448: iOS 9.3.3
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4448
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
Apple
CVE-2016-4448: tvOS 9.2.2
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4448
Component: Kernel
Impact: A local user may be able to cause a system denial of service
Description: A null pointer dereference was addressed through improved input validation.
Red Hat
libxml2: Format string vulnerability
vendor_redhat·2016-05-23·CVSS 9.8
CVE-2016-4448 [CRITICAL] CWE-134 libxml2: Format string vulnerability
libxml2: Format string vulnerability
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 3) - Affected
Debian
CVE-2016-4448: libxml2 - Format string vulnerability in libxml2 before 2.9.4 allows attackers to have uns...
vendor_debian·2016·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448: libxml2 - Format string vulnerability in libxml2 before 2.9.4 allows attackers to have uns...
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Scope: local
bookworm: resolved (fixed in 2.9.4+dfsg1-1)
bullseye: resolved (fixed in 2.9.4+dfsg1-1)
forky: resolved (fixed in 2.9.4+dfsg1-1)
sid: resolved (fixed in 2.9.4+dfsg1-1)
trixie: resolved (fixed in 2.9.4+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-a
bugzilla·2016-06-24·CVSS 8.1
CVE-2016-1762 [HIGH] CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-a
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 libxml2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE
Bugzilla
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fe
bugzilla·2016-06-24·CVSS 8.1
CVE-2016-1762 [HIGH] CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fe
CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-4447 CVE-2016-4448 CVE-2016-4449 mingw-libxml2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention t
Bugzilla
CVE-2016-4448 libxml2: Format string vulnerability
bugzilla·2016-05-23·CVSS 9.8
CVE-2016-4448 [CRITICAL] CVE-2016-4448 libxml2: Format string vulnerability
CVE-2016-4448 libxml2: Format string vulnerability
A vulnerability was found in the libxml2 library. There exist a possible format string vulnerability.
https://bugzilla.gnome.org/show_bug.cgi?id=761029
Upstream fixes:
https://git.gnome.org/browse/libxml2/commit/?id=4472c3a5a5b516aaf59b89be602fbce52756c3e9
https://git.gnome.org/browse/libxml2/commit/?id=502f6a6d08b08c04b3ddfb1cd21b2f699c1b7f5b
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1292 https://access.redhat.com/errata/RHSA-2016:1292
---
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349794]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349795]
---
This issue has been
Tenable
Critical Vulnerability Fixes Available For Juniper Devices
blogs_tenable·2019-01-10
Critical Vulnerability Fixes Available For Juniper Devices
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Critical Vulnerability Fixes Available For Juniper Devices
blogs_tenable·2019-01-10·CVSS 9.8
[CRITICAL] Critical Vulnerability Fixes Available For Juniper Devices
Blog / Cyber Exposure Alerts
Subscribe
# Critical Vulnerability Fixes Available For Juniper Devices
Ryan Seguin
January 10, 2019
2 Min Read
Juniper has addressed multiple critical vulnerabilities in Junos, Junos Space, and JATP devices. Administrators are advised to update to the latest OS version on any affected Juniper device.
## Background
Juniper has released a number of security advisories this week which include critical vulnerabilities across many of its devices. The Juniper Advanced Threat Prevention Appliance (JATP) update removes hardcoded admin credentials, while the Junos updates include patches for remote code execution (RCE) and denial of service (DoS) vulnerabilities. Junos Space network management devices are also vulnerable to a memory allocation vulnerability which
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-01-31
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.openwall.com/lists/oss-security/2016/05/25/2http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90856http://www.securitytracker.com/id/1036348http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.404722http://xmlsoft.org/news.htmlhttps://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.redhat.com/show_bug.cgi?id=1338700https://git.gnome.org/browse/libxml2/commit/?id=4472c3a5a5b516aaf59b89be602fbce52756c3e9https://git.gnome.org/browse/libxml2/commit/?id=502f6a6d08b08c04b3ddfb1cd21b2f699c1b7f5bhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05194709https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://support.apple.com/HT206899https://support.apple.com/HT206901https://support.apple.com/HT206902https://support.apple.com/HT206903https://support.apple.com/HT206904https://support.apple.com/HT206905https://www.tenable.com/security/tns-2016-18http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.openwall.com/lists/oss-security/2016/05/25/2http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90856http://www.securitytracker.com/id/1036348http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.404722http://xmlsoft.org/news.htmlhttps://access.redhat.com/errata/RHSA-2016:1292https://bugzilla.redhat.com/show_bug.cgi?id=1338700https://git.gnome.org/browse/libxml2/commit/?id=4472c3a5a5b516aaf59b89be602fbce52756c3e9https://git.gnome.org/browse/libxml2/commit/?id=502f6a6d08b08c04b3ddfb1cd21b2f699c1b7f5bhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05194709https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://support.apple.com/HT206899https://support.apple.com/HT206901https://support.apple.com/HT206902https://support.apple.com/HT206903https://support.apple.com/HT206904https://support.apple.com/HT206905https://www.tenable.com/security/tns-2016-18
2016-06-09
Published