cbcvebase.
CVE-2017-7376
published 2018-02-19

CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleios
appleitunes_12.7_for_windows
applemacos_high_sierra
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
appletvos
applewatchos_4
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.9.4+dfsg1-3.1 (bookworm)libxml2 2.9.4+dfsg1-3.1 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
xmlsoftlibxml2< 2.9.52.9.5
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-3.12.9.4+dfsg1-3.1
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.102.9.1+dfsg1-3ubuntu4.10

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL