CVE-2016-3705
17.05.2016, 14:08
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.10 |
canonical | ubuntu_linux | 16.04 |
xmlsoft | libxml2 | 2.9.3 |
debian | debian_linux | 8.0 |
hp | icewall_federation_agent | 3.0 |
hp | icewall_file_manager | 3.0 |
opensuse | leap | 42.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References