ALPINE-CVE-2017-5969 PUBLISHED CVSS 4.699999809265137 MEDIUM

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

Risk Scores

CVSS v3.0
4.699999809265137
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.20libxml22.9.0-r1, 2.7.7-r1, 0
Alpine:v3.9libxml22.8.0-r1, 2.9.4-r3, 2.9.4-r2
Alpine:v3.18libxml20, 0, 2.7.2-r0
Alpine:v3.17libxml20, 2.9.0-r0, 2.9.0-r1
Alpine:v3.23libxml22.7.7-r2, 2.9.4-r2, 2.9.4-r1
Alpine:v3.3libxml22.9.4-r2, 2.9.4-r1, 2.9.4-r0
Alpine:v3.10libxml22.9.1-r1, 2.7.3-r0, 2.7.6-r0
Alpine:v3.6libxml22.9.4-r3, 2.9.4-r2, 2.9.4-r1
Alpine:v3.16libxml22.7.7-r3, 2.9.0-r3, 2.9.1-r0
Alpine:v3.12libxml22.9.4-r3, 0, 2.7.2-r0
Alpine:v3.15libxml22.7.7-r4, 2.9.0-r1, 2.9.0-r2
Alpine:v3.8libxml22.9.4-r3, 2.7.3-r0, 2.7.6-r0
Alpine:v3.2libxml20, 2.7.6-r0, 2.7.6-r2
Alpine:v3.19libxml22.9.0-r1, 0, 2.7.2-r0
Alpine:v3.7libxml22.9.2-r2, 2.7.3-r0, 2.7.6-r0
Alpine:v3.4libxml22.7.8-r4, 2.9.4-r2, 2.9.4-r1
Alpine:v3.14libxml22.7.8-r7, 2.7.8-r6, 2.7.8-r5
Alpine:v3.13libxml22.9.0-r0, 0, 2.7.2-r0
Alpine:v3.22libxml20, 2.9.4-r3, 2.9.4-r2
Alpine:v3.11libxml20, 2.9.4-r3, 2.9.4-r2

…and 2 more

Timeline

References

Open in Interactive Console →