CVE-2016-5131
published 2016-07-23CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or…
PriorityP336high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.27%
81.1th percentile
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 10.0 | 10.0 |
| apple | mac_os_x | < 10.12 | 10.12 |
| apple | macos_sierra | — | — |
| apple | tvos | < 10.0 | 10.0 |
| apple | tvos | — | — |
| apple | watchos | < 3.0 | 3.0 |
| apple | watchos_3 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-2.1 (bookworm) | libxml2 2.9.4+dfsg1-2.1 (bookworm) |
| android | — | — | |
| chrome | < 52.0.2743.82 | 52.0.2743.82 | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise | — | — |
| xmlsoft | libxml2 | <= 2.9.4 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-2.1 | 2.9.4+dfsg1-2.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-2.1 | 2.9.4+dfsg1-2.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Android
CVE-2016-5131: Android Security Bulletin 2017-05-01
CVE: CVE-2016-5131
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2017-05-01·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: Android Security Bulletin 2017-05-01
CVE: CVE-2016-5131
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2017-05-01
CVE: CVE-2016-5131
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0
References: A-32956747*
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2017-03-16·CVSS 9.8
CVE-2016-4448 [CRITICAL] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled format strings. If a
user or automated system were tricked into opening a specially crafted
document, an attacker could possibly cause libxml2 to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04
LTS, and Ubuntu 16.04 LTS. (CVE-2016-4448)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-4658)
Nick Wellnhofer discovered that libxml2 incorrectly handled certain
malformed
Apple
CVE-2016-5131: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-5131
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2016-5131: iOS 10
vendor_apple·2016-09-13·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-5131
Component: Keyboards
Impact: Keyboard auto correct suggestions may reveal sensitive information
Description: The iOS keyboard was inadvertently caching sensitive information. This issue was addressed through improved heuristics.
Apple
CVE-2016-5131: tvOS 10
vendor_apple·2016-09-13·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: tvOS 10
Apple Security Update: About the security content of tvOS 10
Product: tvOS
Version: 10
CVE: CVE-2016-5131
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2016-5131: watchOS 3
vendor_apple·2016-09-13·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: watchOS 3
Apple Security Update: About the security content of watchOS 3
Product: watchOS 3
CVE: CVE-2016-5131
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovere
Red Hat
libxml2: Use after free triggered by XPointer paths beginning with range-to
vendor_redhat·2016-07-20·CVSS 8.8
CVE-2016-5131 [HIGH] libxml2: Use after free triggered by XPointer paths beginning with range-to
libxml2: Use after free triggered by XPointer paths beginning with range-to
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Statement: This flaw in libxml2 requires exposing the library to XPath/XPointer expressions from an untrusted source, which is not common in practice for applications using libxml2. For libxml2, Red Hat Product Security has rated this vulnerability as Moderate severity.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat Enterprise Linux 6) - Will not fix
Package: libxml2 (Red Hat Enterprise Linux 8) - Not affected
Package: ming
Debian
CVE-2016-5131: libxml2 - Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome ...
vendor_debian·2016·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: libxml2 - Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome ...
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Scope: local
bookworm: resolved (fixed in 2.9.4+dfsg1-2.1)
bullseye: resolved (fixed in 2.9.4+dfsg1-2.1)
forky: resolved (fixed in 2.9.4+dfsg1-2.1)
sid: resolved (fixed in 2.9.4+dfsg1-2.1)
trixie: resolved (fixed in 2.9.4+dfsg1-2.1)
GHSA
GHSA-m2p3-mc6m-w9j7: Use-after-free vulnerability in libxml2 through 2
ghsa_unreviewed·2022-05-14
CVE-2016-5131 [HIGH] CWE-416 GHSA-m2p3-mc6m-w9j7: Use-after-free vulnerability in libxml2 through 2
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
OSV
libxml2 vulnerabilities
osv·2017-03-16·CVSS 9.8
CVE-2016-4448 [CRITICAL] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled format strings. If a
user or automated system were tricked into opening a specially crafted
document, an attacker could possibly cause libxml2 to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04
LTS, and Ubuntu 16.04 LTS. (CVE-2016-4448)
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could cause libxml2 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-4658)
Nick Wellnhofer discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
openi
OSV
oxide-qt vulnerabilities
osv·2016-08-05·CVSS 8.8
CVE-2016-1705 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service (application crash) or execute arbitrary code. (CVE-2016-1705)
It was discovered that the PPAPI implementation does not validate the
origin of IPC messages to the plugin broker process. A remote attacker
could potentially exploit this to bypass sandbox protection mechanisms.
(CVE-2016-1706)
It was discovered that Blink does not prevent window creation by a
deferred frame. A remote attacker could potentially exploit this to bypass
same origin restrictions. (CVE-2016-1710)
It was discovered that Blink does not disable frame navigation during a
det
OSV
CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2
osv·2016-07-23·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5131 mingw-libxml2: libxml2: use after free triggered by XPointer paths beginning with range-to [epel-7]
bugzilla·2016-08-05·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131 mingw-libxml2: libxml2: use after free triggered by XPointer paths beginning with range-to [epel-7]
CVE-2016-5131 mingw-libxml2: libxml2: use after free triggered by XPointer paths beginning with range-to [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatica
Bugzilla
CVE-2016-5131 mingw-libxml2: chromium-browser: use-after-free in libxml [fedora-all]
bugzilla·2016-08-05·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131 mingw-libxml2: chromium-browser: use-after-free in libxml [fedora-all]
CVE-2016-5131 mingw-libxml2: chromium-browser: use-after-free in libxml [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-5131 libxml2: chromium-browser: use-after-free in libxml [fedora-all]
bugzilla·2016-07-29·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131 libxml2: chromium-browser: use-after-free in libxml [fedora-all]
CVE-2016-5131 libxml2: chromium-browser: use-after-free in libxml [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to
bugzilla·2016-07-21·CVSS 8.8
CVE-2016-5131 [HIGH] CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to
CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to
An use-after-free flaw was found in the libxml component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=623378
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1485 https://rhn.redhat.com/errata/RHSA-2016-1485.html
---
Detailed analysis and explanation available in the upstream bug (currently closed) at:
https://bugzilla.gnome.org/show_bug.cgi?id=768428
Chromium used the following patch to fix this issue (not upstream yet):
https://codereview.chromium.org/2127493002
---
arXiv
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
arxiv_fulltext·2019-05-22
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
1.55cm
[1]
\@fnsymbol#1
Hey Google, What Exactly Do Your Security Patches Tell Us?\ Large-Scale Empirical Study on Android Patched Vulnerabilities
Sadegh Farhang Sadegh Farhang and Mehmet Bahadir Kirdan equally contributed to this work.
Pennsylvania State University
[email protected]
Mehmet Bahadir Kirdan 1
Technical University of Munich
[email protected]
Aron Laszka
University of Houston
[email protected]
Jens Grossklags
Technical University of Munich
[email protected]
## Abstract
Android has the largest market share among smartphone platforms worldwide with more than one billion active devices.
Like other platforms, security patches play a pivotal role in keeping Android devices safe from the exploitation of known vulnerabilities. Previous research efforts have documente
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00010.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.securitytracker.com/id/1038623http://www.ubuntu.com/usn/USN-3041-1https://bugzilla.redhat.com/show_bug.cgi?id=1358641https://codereview.chromium.org/2127493002https://crbug.com/623378https://security.gentoo.org/glsa/201610-09https://security.gentoo.org/glsa/201701-37https://source.android.com/security/bulletin/2017-05-01https://support.apple.com/HT207141https://support.apple.com/HT207142https://support.apple.com/HT207143https://support.apple.com/HT207170http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00010.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1485.htmlhttp://www.debian.org/security/2016/dsa-3637http://www.securityfocus.com/bid/92053http://www.securitytracker.com/id/1036428http://www.securitytracker.com/id/1038623http://www.ubuntu.com/usn/USN-3041-1https://bugzilla.redhat.com/show_bug.cgi?id=1358641https://codereview.chromium.org/2127493002https://crbug.com/623378https://security.gentoo.org/glsa/201610-09https://security.gentoo.org/glsa/201701-37https://source.android.com/security/bulletin/2017-05-01https://support.apple.com/HT207141https://support.apple.com/HT207142https://support.apple.com/HT207143https://support.apple.com/HT207170
2016-07-23
Published