CVE-2017-7376

Severity
9.8CRITICAL
EPSS
38.4%
top 2.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 14

Description

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDxmlsoft/libxml2< 2.9.5
Debianlibxml2< 2.9.4+dfsg1-3.1+3
NVDgoogle/android8 versions+7

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-j45j-3c7p-vf8f: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects2022-05-14
CVEList
CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects2018-02-19
OSV
CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects2018-02-19
OSV
libxml2 vulnerabilities2017-09-19

📋Vendor Advisories

12
Apple
CVE-2017-7376: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan2017-10-31
Ubuntu
libxml2 vulnerabilities2017-10-10
Apple
CVE-2017-7376: iCloud for Windows 7.02017-09-25
Apple
CVE-2017-7376: macOS High Sierra 10.132017-09-25
Ubuntu
libxml2 vulnerabilities2017-09-19

💬Community

4
Bugzilla
CVE-2017-7376 libxml2: Incorrect limit used for port values2017-06-16
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 libxml2: various flaws [fedora-all]2017-06-16
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 mingw-libxml2: various flaws [fedora-all]2017-06-16
Bugzilla
CVE-2017-0663 CVE-2017-7375 CVE-2017-7376 mingw-libxml2: various flaws [epel-7]2017-06-16
CVE-2017-7376 (CRITICAL CVSS 9.8) | Buffer overflow in libxml2 allows r | cvebase.io