CVE-2016-5131

CWE-416Use After Free17 documents10 sources
Severity
8.8HIGH
EPSS
3.9%
top 11.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages12 packages

NVDgoogle/chrome< 52.0.2743.82
Debianlibxml2< 2.9.4+dfsg1-2.1+3
NVDxmlsoft/libxml22.9.4
NVDapple/tvos< 10.0
NVDapple/watchos< 3.0

Also affects: Debian Linux 8.0, 9.0, Linux Enterprise 12.0, Ubuntu Linux 14.04, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-m2p3-mc6m-w9j7: Use-after-free vulnerability in libxml2 through 22022-05-14
CVEList
CVE-2016-5131: Use-after-free vulnerability in libxml2 through 22016-07-23
OSV
CVE-2016-5131: Use-after-free vulnerability in libxml2 through 22016-07-23

📋Vendor Advisories

9
Android
CVE-2016-5131: Android Security Bulletin 2017-05-01 CVE: CVE-2016-5131 Severity: HIGH Affected AOSP versions: 42017-05-01
Ubuntu
libxml2 vulnerabilities2017-03-16
Apple
CVE-2016-5131: macOS Sierra 10.122016-09-20
Apple
CVE-2016-5131: iOS 102016-09-13
Apple
CVE-2016-5131: tvOS 102016-09-13

💬Community

4
Bugzilla
CVE-2016-5131 mingw-libxml2: libxml2: use after free triggered by XPointer paths beginning with range-to [epel-7]2016-08-05
Bugzilla
CVE-2016-5131 mingw-libxml2: chromium-browser: use-after-free in libxml [fedora-all]2016-08-05
Bugzilla
CVE-2016-5131 libxml2: chromium-browser: use-after-free in libxml [fedora-all]2016-07-29
Bugzilla
CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to2016-07-21