Lucene search

K
f5F5F5:K24322529
HistoryDec 07, 2016 - 12:00 a.m.

K24322529 : libxml2 vulnerabilities CVE-2016-4447 and CVE-2016-4449

2016-12-0700:00:00
my.f5.com
22

8.1 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.3%

Security Advisory Description

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Impact

  • CVE-2016-4447

An attacker can craft an XML document to cause the application to stop responding, thereby resulting in a denial-of-service (DoS) attack.

  • CVE-2016-4449

An attacker may read arbitrary files or cause a DoS attack when the vulnerability is exploited.