VDB

ALINUX2-SA-2021%3A0058

ALINUX2-SA-2021%3A0058 PUBLISHED CVSS 5.300000190734863 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2016-4658: xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

Risk Scores

CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Alibaba Cloudlibxml2

Timeline

  • Oct 13, 2021 CVE Published
  • Oct 13, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›