CVE-2017-16932
Severity
7.5HIGH
EPSS
22.0%
top 4.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 13
Description
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
5📋Vendor Advisories
5Debian▶
CVE-2017-16932: libxml2 - parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in paramete...↗2017
💬Community
6Bugzilla▶
CVE-2017-16932 mingw-libxml2: libxml2: Infinite recursion in parameter entities [fedora-all]↗2017-11-24
Bugzilla▶
CVE-2017-16932 rubygem-nokogiri: libxml2: Infinite recursion in parameter entities [fedora-all]↗2017-11-24
Bugzilla▶
CVE-2017-16932 rubygem-nokogiri: libxml2: Infinite recursion in parameter entities [epel-all]↗2017-11-24