CVE-2016-4483 PUBLISHED

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.

EPSS 1.27% · 79.4th percentile

Risk Scores

EPSS Score
1.27%
79.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibxml20, 2.9.2+zdfsg1-4, 2.9.2+zdfsg1-4ubuntu1
Ubuntu:14.04:LTSlibxml22.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 0

Timeline

References

Open in Interactive Console →