cbcvebase.
CVE-2017-5130
published 2018-02-07

CVE-2017-5130: An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleios
appleitunes_12.7_for_windows
applemacos_high_sierra
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
appletvos
applewatchos_4
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.9.4+dfsg1-5.1 (bookworm)libxml2 2.9.4+dfsg1-5.1 (bookworm)
googlechrome< 62.0.3202.6262.0.3202.62
xmlsoftlibxml2< 2.9.52.9.5
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-5.12.9.4+dfsg1-5.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-5.12.9.4+dfsg1-5.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-5.12.9.4+dfsg1-5.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-5.12.9.4+dfsg1-5.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH