CVE-2017-7376

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxml2
𝑥
< 2.9.5
googleandroid
4.4.4
googleandroid
5.0.2
googleandroid
5.1.1
googleandroid
6.0
googleandroid
6.0.1
googleandroid
7.0
googleandroid
7.1.1
googleandroid
7.1.2
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml2
trusty
Fixed 2.9.1+dfsg1-3ubuntu4.10
released
xenial
Fixed 2.9.3+dfsg1-1ubuntu0.3
released
yakkety
ignored
zesty
Fixed 2.9.4+dfsg1-2.2ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxml2-2
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-2-32bit
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-doc
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-tools
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
python-libxml2
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed