CVE-2017-0663 PUBLISHED

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

EPSS 1.04% · 77.3th percentile

Risk Scores

EPSS Score
1.04%
77.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibxml20, 2.9.3+dfsg1-1ubuntu0.2, 2.9.3+dfsg1-1ubuntu0.1
Ubuntu:16.04:LTSandroid20160330-0939-0ubuntu1, 0, 20150818-1500-0ubuntu2
Ubuntu:14.04:LTSlibxml22.9.1+dfsg1-3ubuntu4.5, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.3

Timeline

References

Open in Interactive Console →