Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6363
HistoryMay 23, 2018 - 8:03 a.m.

Denial Of Service (DoS)

2018-05-2308:03:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.011

Percentile

84.4%

libxml2.so is vulnerable to denial of service. The vulnerability exists in the xmlParserEntityCheck and xmlParseAttValueComplex functions that calls xmlStringDecodeEntities recursively without incrementing the depth counter, causing a stack buffer overflow attack which then lead to an application crash.

References