First published: Thu Nov 23 2017(Updated: )
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xmlsoft Libxml2 | <=2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16931 is a vulnerability in libxml2 before version 2.9.5 that mishandles parameter-entity references.
The severity of CVE-2017-16931 is critical with a CVSS score of 9.8.
CVE-2017-16931 affects the Xmlsoft Libxml2 library version up to and including 2.9.4.
The CWE ID for CVE-2017-16931 is 119.
Yes, the fix for CVE-2017-16931 is available in libxml2 version 2.9.5.