CVE-2017-16932

Severity
7.5HIGH
EPSS
22.0%
top 4.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 13

Description

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debianlibxml2< 2.9.10+dfsg-2+3
Ubuntulibxml2< 2.9.1+dfsg1-3ubuntu4.13+2
NVDxmlsoft/libxml22.9.4
RubyGemsnokogiri< 1.8.1

Patches

🔴Vulnerability Details

5
GHSA
Nokogiri gem, via libxml, is affected by DoS vulnerabilities2022-05-13
OSV
Nokogiri gem, via libxml, is affected by DoS vulnerabilities2022-05-13
OSV
libxml2 vulnerabilities2018-08-14
OSV
CVE-2017-16932: parser2017-11-23
CVEList
CVE-2017-16932: parser2017-11-23

📋Vendor Advisories

5
Ubuntu
libxml2 vulnerabilities2018-08-14
Ubuntu
libxml2 vulnerability2017-12-05
Ubuntu
libxml2 vulnerability2017-12-05
Red Hat
libxml2: Infinite recursion in parameter entities2017-07-25
Debian
CVE-2017-16932: libxml2 - parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in paramete...2017

💬Community

6
Bugzilla
CVE-2017-16932 mingw-libxml2: libxml2: Infinite recursion in parameter entities [fedora-all]2017-11-24
Bugzilla
CVE-2017-16932 libxml2: Infinite recursion in parameter entities [fedora-all]2017-11-24
Bugzilla
CVE-2017-16932 rubygem-nokogiri: libxml2: Infinite recursion in parameter entities [fedora-all]2017-11-24
Bugzilla
CVE-2017-16932 libxml2: Infinite recursion in parameter entities2017-11-24
Bugzilla
CVE-2017-16932 rubygem-nokogiri: libxml2: Infinite recursion in parameter entities [epel-all]2017-11-24
CVE-2017-16932 (HIGH CVSS 7.5) | parser.c in libxml2 before 2.9.5 do | cvebase.io