CVE-2017-16931: Buffer Overflow
Published Nov 23, 2017
·Updated
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
Affected Software
1 affected component
XMLSoft Libxml2<=2.9.4
Remediation
Event History
Nov 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-16931?
CVE-2017-16931 is a vulnerability in libxml2 before version 2.9.5 that mishandles parameter-entity references.
2
What is the severity of CVE-2017-16931?
The severity of CVE-2017-16931 is critical with a CVSS score of 9.8.
3
How does CVE-2017-16931 affect software?
CVE-2017-16931 affects the Xmlsoft Libxml2 library version up to and including 2.9.4.
4
What is the CWE ID for CVE-2017-16931?
The CWE ID for CVE-2017-16931 is 119.
5
Is there a fix for CVE-2017-16931?
Yes, the fix for CVE-2017-16931 is available in libxml2 version 2.9.5.