CVE-2017-10672: Use After Free
Published Jun 29, 2017
·Updated
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
Affected Software
5 affected componentsFixes available
debian/libxml-libxml-perl<=2.0128+dfsg-3, <=2.0116+dfsg-1
2.0128+dfsg-42.0128+dfsg-1+deb9u12.0116+dfsg-1+deb8u2
debian/libxml-libxml-perl
2.0134+dfsg-12.0134+dfsg-22.0207+dfsg+really+2.0134-1
Xml-libxml Project Xml-libxml Perl<=2.0129
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jun 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10672?
CVE-2017-10672 has been categorized as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2017-10672?
To fix CVE-2017-10672, upgrade the affected libxml-libxml-perl package to version 2.0130 or later.
3
What software is affected by CVE-2017-10672?
CVE-2017-10672 affects versions of the libxml-libxml-perl package prior to 2.0130.
4
Can CVE-2017-10672 be exploited remotely?
Yes, CVE-2017-10672 can be exploited remotely by attackers through crafted input.
5
What are the consequences of CVE-2017-10672 being exploited?
Exploitation of CVE-2017-10672 can lead to arbitrary code execution, compromising the affected system.