CVE-2016-5131: Use After Free
An use-after-free flaw was found in the libxml component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=623378
External References:
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html
Other sources
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5131?
CVE-2016-5131 has a high severity level due to the potential for denial of service and other unspecified impacts.
How do I fix CVE-2016-5131?
To fix CVE-2016-5131, upgrade Google Chrome to version 52.0.2743.82 or later, and libxml2 to version 2.9.5 or later.
What software is affected by CVE-2016-5131?
CVE-2016-5131 affects Google Chrome versions prior to 52.0.2743.82 and libxml2 versions up to 2.9.4.
What type of vulnerability is CVE-2016-5131?
CVE-2016-5131 is classified as a use-after-free vulnerability.
Can CVE-2016-5131 be exploited remotely?
Yes, CVE-2016-5131 can be exploited remotely, allowing attackers to cause denial of service.