First published: Mon Mar 21 2016(Updated: )
It was found that Red Hat JBoss Core Services incorrectly fixed <a href="https://access.redhat.com/security/cve/CVE-2016-3627">CVE-2016-3627</a> in Apache HTTP 2.4.23 (erratum RHSA-2016:2957), leaving libxml2 vulnerable to a Denial of Service attack via stack consumption.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Core Services | ||
libxml2-devel | <2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9596 has been assigned a high severity rating due to its potential to cause Denial of Service attacks.
To fix CVE-2016-9596, you should upgrade to a version of libxml2 that is above 2.9.4.
CVE-2016-9596 affects Red Hat JBoss Core Services and libxml2 versions up to 2.9.4.
CVE-2016-9596 is a Denial of Service vulnerability related to stack consumption in libxml2.
Yes, CVE-2016-9596 allows attackers to exploit the vulnerability remotely to launch Denial of Service attacks.