cbcvebase.
CVE-2016-4449
published 2016-06-09

CVE-2016-4449: XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows…

high7.1CVSS 3.0
AVLACLPRNUIRSUCHINAH
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleios
appleitunes_12.4.2_for_windows
appleos_x_el_capitan_v10.11.6_and_security_update_2016-004
appletvos
applewatchos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibxml2< libxml2 2.9.3+dfsg1-1.1 (bookworm)libxml2 2.9.3+dfsg1-1.1 (bookworm)
xmlsoftlibxml2<= 2.9.3
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1.12.9.3+dfsg1-1.1
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1.12.9.3+dfsg1-1.1
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1.12.9.3+dfsg1-1.1
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1.12.9.3+dfsg1-1.1
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.82.9.1+dfsg1-3ubuntu4.8
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1ubuntu0.12.9.3+dfsg1-1ubuntu0.1

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.5HIGH