First published: Mon May 23 2016(Updated: )
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP IceWall Federation Agent | =3.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Apple iOS, iPadOS, and watchOS | <=2.2.1 | |
Apple iOS and macOS | <10.11.6 | |
libxml2 | <=2.9.3 | |
Apple iCloud for Windows | <5.2.1 | |
Microsoft Windows | ||
iOS | <=9.3.2 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.2 | |
redhat enterprise Linux server aus | =7.3 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server eus | =7.2 | |
redhat enterprise Linux server eus | =7.3 | |
redhat enterprise Linux server eus | =7.4 | |
redhat enterprise Linux server eus | =7.5 | |
redhat enterprise Linux server eus | =7.6 | |
redhat enterprise Linux server eus | =7.7 | |
redhat enterprise Linux server tus | =7.2 | |
redhat enterprise Linux server tus | =7.3 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
Apple iTunes for Windows | <=12.4.1 | |
Microsoft Windows | ||
Slackware Linux | =14.0 | |
Slackware Linux | =14.1 | |
Oracle VM Server | =3.3 | |
Oracle VM Server | =3.4 | |
tvOS | <=9.2.1 | |
Tenable Log Correlation Engine | =4.8.0 | |
McAfee Web Gateway | <=7.5.2.10 | |
McAfee Web Gateway | >=7.6.0.0<=7.6.2.3 | |
Oracle Linux | =6 | |
Oracle Linux | =7-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4448 has not been assigned a specific CVSS score but is categorized as a format string vulnerability in libxml2.
To fix CVE-2016-4448, update libxml2 to version 2.9.4 or later.
CVE-2016-4448 affects versions of libxml2 prior to 2.9.4, and certain software relying on older versions of this library.
CVE-2016-4448 allows attackers to potentially execute arbitrary code via crafted input that exploits the format string vulnerability.
To determine if your system is vulnerable to CVE-2016-4448, check if you are using libxml2 version 2.9.3 or earlier.