First published: Thu Nov 23 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libxml2 | 2.9.10+dfsg-6.7+deb11u4 2.9.10+dfsg-6.7+deb11u5 2.9.14+dfsg-1.3~deb12u1 2.12.7+dfsg+really2.9.14-0.2 | |
libxml2-devel | <=2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16932 is a vulnerability in libxml2 that allows for infinite recursion in parameter entities.
CVE-2017-16932 has a severity rating of 7.5 (High).
CVE-2017-16932 affects libxml2 versions before 2.9.5.
To fix CVE-2017-16932, update libxml2 to version 2.9.5 or higher.
You can find more information about CVE-2017-16932 on the following websites: [http://xmlsoft.org/news.html](http://xmlsoft.org/news.html), [https://bugzilla.gnome.org/show_bug.cgi?id=759579](https://bugzilla.gnome.org/show_bug.cgi?id=759579), [https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961](https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961).