CVE-2017-16931
23.11.2017, 21:29
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xmlsoft | libxml2 | 𝑥 ≤ 2.9.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| libxml2 |
| ||||
| libxml2-debuginfo |
| ||||
| libxml2-devel |
| ||||
| libxml2-python |
| ||||
| libxml2-python26 |
| ||||
| libxml2-python27 |
| ||||
| libxml2-static |
|
Common Weakness Enumeration
References