Back

CRITICAL

libxml2: Use after free via namespace node in XPointer ranges

Published Sep 25, 2016

Description

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

Affected products

Remediation

Red Hat statement

This flaw can be triggered by parsing untrusted XML files via applications compiled with libxml2 causing the application to crash. For web browsers or browser like applications, which parse untrusted web content, it may be possible to trigger this flaw without any user intervention and cause remote code execution with the permissions of the user running the browser. For other applications this flaw is difficult to trigger and even difficult to exploit in real life situations. The status of mingw-libxml2 package in RHEL-8 is marked as "not-affected" because it does not impact end-users.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Sep 25, 2016
Updated Aug 6, 2024
Reserved May 11, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 12, 2016
GHSA-FR52-4HQW-P27F