CVE-2017-0663Out-of-bounds Write in Libxml2

Severity
7.8HIGHNVD
EPSS
1.0%
top 22.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateDec 14

Description

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDgoogle/android8 versions+7
CVEListV5google_inc/androidAndroid-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2
debiandebian/libxml2< libxml2 2.9.4+dfsg1-3.1 (bookworm)
Debianxmlsoft/libxml2< 2.9.4+dfsg1-3.1+3

🔴Vulnerability Details

3
GHSA
GHSA-9cf7-h7g3-cg3p: A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context2022-05-13
OSV
libxml2 vulnerabilities2017-09-19
OSV
CVE-2017-0663: A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context2017-06-14

📋Vendor Advisories

6
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14
Ubuntu
libxml2 vulnerabilities2017-10-10
Ubuntu
libxml2 vulnerabilities2017-09-19
Android
CVE-2017-0663: Android Security Bulletin 2017-06-01 CVE: CVE-2017-0663 Severity: HIGH Type: RCE Affected AOSP versions: 42017-06-01
Red Hat
libxml2: Heap buffer overflow in xmlAddID2017-04-17

💬Community

4
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 libxml2: various flaws [fedora-all]2017-06-16
Bugzilla
CVE-2017-0663 libxml2: Heap buffer overflow in xmlAddID2017-06-16
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 mingw-libxml2: various flaws [fedora-all]2017-06-16
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 mingw-libxml2: various flaws [epel-7]2017-06-16