cbcvebase.
CVE-2017-7376
published 2018-02-19

CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
23.69%
97.6th percentile
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleios
appleitunes_12.7_for_windows
applemacos_high_sierra
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
appletvos
applewatchos_4
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.9.4+dfsg1-3.1 (bookworm)libxml2 2.9.4+dfsg1-3.1 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
xmlsoftlibxml2< 2.9.52.9.5
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.102.9.1+dfsg1-3ubuntu4.10

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2017-7376 is a buffer overflow in libxml2 triggered by an incorrect limit for port values when handling HTTP redirects; monitor for anomalously large port values in redirect URLs processed by libxml2-linked applications
  • Android devices running AOSP versions 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, and 7.1.2 are affected with HIGH severity RCE classification; patch status should be verified against the 2017-06-01 Android Security Bulletin
  • ·Red Hat Enterprise Linux 5, 6, 7, and 8 packages of libxml2 are all marked 'Not affected'; detection/patching efforts on RHEL platforms for this CVE are not required
  • ·Apple advisory pages cross-reference CVE-2017-7376 with unrelated CVEs and components (e.g., CVE-2017-9233, ImageIO, Kernel) across multiple products (iTunes, watchOS, tvOS, macOS); the CVE-to-component mapping in Apple advisories appears inconsistent and should not be used as the sole basis for scoping impact

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.