Back

HIGH

libxml2: out-of-bounds read

Published Apr 11, 2017

Description

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.

Affected products

Remediation

Red Hat statement

When a specially-crafted XML file is parsed via an application compiled against libxml2, this can cause the application to crash. (No code execution)

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 11, 2017
Updated Aug 6, 2024
Reserved May 4, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 3, 2016