CVE-2016-9597
published 2018-07-30CVE-2016-9597: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.48%
90.4th percentile
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | — | — |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| opensuse | leap | — | — |
| xmlsoft | libxml2 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-94gc-v83r-7m7w: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2016-9597 [HIGH] CWE-119 GHSA-94gc-v83r-7m7w: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Red Hat
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
vendor_redhat·2016-05-03·CVSS 7.5
CVE-2016-9597 [HIGH] CWE-674 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 6) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat JBoss Core Services) - Affected
Debian
CVE-2016-9597: libxml2 - It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-201...
vendor_debian·2016·CVSS 7.5
CVE-2016-9597 [HIGH] CVE-2016-9597: libxml2 - It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-201...
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9597 [HIGH] CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
CVE-2016-9597 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
It was found that Red Hat JBoss Core Services incorrectly included CVE-2016-3705 as resolved in Apache HTTP 2.4.23 (erratum RHSA-2016:2957). The release did not include the fix to libxml2, leaving it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for CVE-2016-3705.
Discussion:
Are there any details available for this? Upsteam bug, commit reference?
---
(In reply to Salvatore Bonaccorso from comment #2)
> Are there any details available for this? Upsteam bug, commit reference?
Referring to https://bugzilla.redhat.com/show_bug.cgi?id=1408302#c4
---
Hi Adam
Thanks for the information here and in the related bugs. I guess there is though s
Bugzilla
CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9596 [HIGH] CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
It was found that Red Hat JBoss Core Services incorrectly fixed CVE-2016-3627 in Apache HTTP 2.4.23 (erratum RHSA-2016:2957), leaving libxml2 vulnerable to a Denial of Service attack via stack consumption.
Discussion:
Are there any details available for this? Upsteam bug, commit reference?
---
(In reply to Salvatore Bonaccorso from comment #2)
> Are there any details available for this? Upsteam bug, commit reference?
This and the other two should be for a Red Hat specific security regressions, effectively duplicates of other public CVEs. I'm going to ask Bharti to fix these bugs up properly.
---
dup of CVE-2016-3627 I would say
---
This CVE id is for the same issue as
Bugzilla
CVE-2016-4658 libxml2: Use after free via namespace node in XPointer ranges
bugzilla·2016-10-13·CVSS 9.8
CVE-2016-4658 [CRITICAL] CVE-2016-4658 libxml2: Use after free via namespace node in XPointer ranges
CVE-2016-4658 libxml2: Use after free via namespace node in XPointer ranges
Possible use after free vulnerability via namespace nodes in XPointer ranges was found.
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=c1d1f7121194036608bf555f08d3062a36fd344b
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1384427]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1384429]
Affects: epel-7 [bug 1384430]
---
(In reply to Adam Mariš from comment #0)
> Possible use after free vulnerability via namespace nodes in XPointer ranges
> was found.
>
> Upstream patch:
>
> https://git.gnome.org/browse/libxml2/commit/
> ?id=c1d1f7121194036608bf555f08d3062a36fd344b
Hello Adam,
We have been monitoring the URL ftp://xml
2018-07-30
Published