CVE-2017-5130
published 2018-02-07CVE-2017-5130: An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.77%
84.6th percentile
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | itunes_12.7_for_windows | — | — |
| apple | macos_high_sierra | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| apple | tvos | — | — |
| apple | watchos_4 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-5.1 (bookworm) | libxml2 2.9.4+dfsg1-5.1 (bookworm) |
| chrome | < 62.0.3202.62 | 62.0.3202.62 | |
| xmlsoft | libxml2 | < 2.9.5 | 2.9.5 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-5.1 | 2.9.4+dfsg1-5.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-5.1 | 2.9.4+dfsg1-5.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-5.1 | 2.9.4+dfsg1-5.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-5.1 | 2.9.4+dfsg1-5.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (LibXML2) — CVE-2017-5130
vendor_oracle·2020-04-15·CVSS 8.8
CVE-2017-5130 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (LibXML2) — CVE-2017-5130
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (LibXML2) vulnerability
CVE: CVE-2017-5130
CVSS: 8.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Apple
CVE-2017-5130: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2017-5130
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access process information maintained by the operating system unrestricted. This issue was addressed with rate limiting.
Red Hat
chromium-browser: heap overflow in libxml2
vendor_redhat·2017-10-17·CVSS 8.8
CVE-2017-5130 [HIGH] chromium-browser: heap overflow in libxml2
chromium-browser: heap overflow in libxml2
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
A heap overflow flaw was found in the libxml2 library. An application compiled with libxml2 using the vulnerable debug-only function xmlMemoryStrdup could be used by an attacker to crash the application or execute arbitrary code with the permission of the user running the application.
Statement: This issue does not affect the libxml library shipped with Red Hat Enterprise Linux because the affected code xmlMemoryStrdup() is a debug-only function that should never be called in production builds. The only exception is xmllint when inv
Apple
CVE-2017-5130: iCloud for Windows 7.0
vendor_apple·2017-09-25·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: iCloud for Windows 7.0
Apple Security Update: About the security content of iCloud for Windows 7.0
Product: iCloud for Windows
Version: 7.0
CVE: CVE-2017-5130
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
Apple
CVE-2017-5130: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-5130
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A null pointer dereference was addressed with improved validation.
Apple
CVE-2017-5130: tvOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2017-5130
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2017-5130: watchOS 4
vendor_apple·2017-09-19·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: watchOS 4
Apple Security Update: About the security content of watchOS 4
Product: watchOS 4
CVE: CVE-2017-5130
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2017-5130: iOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-5130
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
Apple
CVE-2017-5130: iTunes 12.7 for Windows
vendor_apple·2017-09-12·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: iTunes 12.7 for Windows
Apple Security Update: About the security content of iTunes 12.7 for Windows
Product: iTunes 12.7 for Windows
CVE: CVE-2017-5130
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: An information disclosure issue existed in the processing of disk images. This issue was addressed through improved memory management.
Debian
CVE-2017-5130: libxml2 - An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Ch...
vendor_debian·2017·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: libxml2 - An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Ch...
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
Scope: local
bookworm: resolved (fixed in 2.9.4+dfsg1-5.1)
bullseye: resolved (fixed in 2.9.4+dfsg1-5.1)
forky: resolved (fixed in 2.9.4+dfsg1-5.1)
sid: resolved (fixed in 2.9.4+dfsg1-5.1)
trixie: resolved (fixed in 2.9.4+dfsg1-5.1)
GHSA
GHSA-6vrj-w635-63jg: An integer overflow in xmlmemory
ghsa_unreviewed·2022-05-13
CVE-2017-5130 [HIGH] CWE-190 GHSA-6vrj-w635-63jg: An integer overflow in xmlmemory
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
OSV
CVE-2017-5130: An integer overflow in xmlmemory
osv·2018-02-07·CVSS 8.8
CVE-2017-5130 [HIGH] CVE-2017-5130: An integer overflow in xmlmemory
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
No detection rules found.
No public exploits indexed.
http://bugzilla.gnome.org/show_bug.cgi?id=783026http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/722079https://git.gnome.org/browse/libxml2/commit/?id=897dffbae322b46b83f99a607d527058a72c51edhttps://lists.debian.org/debian-lts-announce/2017/11/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2022/04/msg00004.htmlhttps://security.gentoo.org/glsa/201710-24https://security.netapp.com/advisory/ntap-20190719-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://bugzilla.gnome.org/show_bug.cgi?id=783026http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/722079https://git.gnome.org/browse/libxml2/commit/?id=897dffbae322b46b83f99a607d527058a72c51edhttps://lists.debian.org/debian-lts-announce/2017/11/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2022/04/msg00004.htmlhttps://security.gentoo.org/glsa/201710-24https://security.netapp.com/advisory/ntap-20190719-0001/https://www.oracle.com/security-alerts/cpuapr2020.html
2018-02-07
Published