Severity
6.5MEDIUM
EPSS
0.7%
top 28.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 16
Latest updateMay 13

Description

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-3627.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDxmlsoft/libxml2< 2.9.4

🔴Vulnerability Details

2
GHSA
GHSA-ch7x-55jf-9fgx: libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack cons2022-05-13
CVEList
CVE-2016-9596: libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack cons2018-08-16

📋Vendor Advisories

2
Red Hat
libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)2016-03-21
Debian
CVE-2016-9596: libxml2 - libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allow...2016

💬Community

2
Bugzilla
CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)2016-12-22
Bugzilla
CVE-2016-9598 libxml2: out-of-bounds read (unfixed CVE-2016-4483 in JBCS)2016-12-22
CVE-2016-9596 (MEDIUM CVSS 6.5) | cvebase.io