CVE-2016-4472

Severity
8.1HIGH
EPSS
2.3%
top 15.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateJan 13

Description

The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages5 packages

Debianexpat< 2.1.1-2+3
NVDpython/python2.7.02.7.15+4
Ubuntulibxmltok< 1.2-3ubuntu0.16.04.1~esm2+7

Also affects: Ubuntu Linux 12.04

Patches

🔴Vulnerability Details

5
OSV
libxmltok vulnerabilities2025-01-13
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-855w-qg6f-ffh7: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic2022-05-13
OSV
CVE-2016-4472: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic2016-06-30
CVEList
CVE-2016-4472: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic2016-06-30

📋Vendor Advisories

7
Ubuntu
xmltok library vulnerabilities2025-01-13
Ubuntu
xmltok library vulnerabilities2022-07-19
Apple
CVE-2016-4472: iTunes 12.6 for Windows2017-03-21
Apple
CVE-2016-4472: iTunes 12.62017-03-21
Ubuntu
XML-RPC for C and C++ vulnerabilities2016-06-20

💬Community

6
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows [fedora-all]2016-06-09
Bugzilla
CVE-2016-4472 expat21: expat: Undefined behavior and pointer overflows [epel-all]2016-06-09
Bugzilla
CVE-2016-4472 mingw-expat: expat: Undefined behavior and pointer overflows [epel-7]2016-06-09
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows2016-06-09
Bugzilla
CVE-2016-4472 mingw-expat: expat: Undefined behavior and pointer overflows [fedora-all]2016-06-09
CVE-2016-4472 (HIGH CVSS 8.1) | The overflow protection in Expat is | cvebase.io