CVE-2017-16932 PUBLISHED

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

EPSS 21.99% · 95.7th percentile

Risk Scores

EPSS Score
21.99%
95.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibxml20, 2.9.4+dfsg1-4ubuntu1, 2.9.4+dfsg1-5ubuntu1
Ubuntu:14.04:LTSlibxml20, 2.9.1+dfsg1-3ubuntu2, 2.9.1+dfsg1-3ubuntu3
Ubuntu:16.04:LTSlibxml20, 2.9.2+zdfsg1-4, 2.9.2+zdfsg1-4ubuntu1

Timeline

References

Open in Interactive Console →