CVE-2017-5969

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*

History

21 Nov 2024, 03:28

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2016/11/05/3 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/11/05/3 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2017/02/13/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2017/02/13/1 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/96188 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/96188 - Third Party Advisory, VDB Entry
References () https://bugzilla.gnome.org/show_bug.cgi?id=778519 - Issue Tracking, Third Party Advisory () https://bugzilla.gnome.org/show_bug.cgi?id=778519 - Issue Tracking, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html - () https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html -
References () https://security.gentoo.org/glsa/201711-01 - () https://security.gentoo.org/glsa/201711-01 -

07 Nov 2023, 02:49

Type Values Removed Values Added
Summary ** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser." libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

Information

Published : 2017-04-11 16:59

Updated : 2024-11-21 03:28


NVD link : CVE-2017-5969

Mitre link : CVE-2017-5969

CVE.ORG link : CVE-2017-5969


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-476

NULL Pointer Dereference