CVE-2017-16932: High severity Xmlsoft Libxml2 vulnerability
Last updated 25 August 2025
Other sources
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-16932?
CVE-2017-16932 is a vulnerability in libxml2 that allows for infinite recursion in parameter entities.
What is the severity of CVE-2017-16932?
CVE-2017-16932 has a severity rating of 7.5 (High).
How does CVE-2017-16932 affect libxml2?
CVE-2017-16932 affects libxml2 versions before 2.9.5.
How can I fix CVE-2017-16932?
To fix CVE-2017-16932, update libxml2 to version 2.9.5 or higher.
Where can I find more information about CVE-2017-16932?
You can find more information about CVE-2017-16932 on the following websites: [http://xmlsoft.org/news.html](http://xmlsoft.org/news.html), [https://bugzilla.gnome.org/show_bug.cgi?id=759579](https://bugzilla.gnome.org/show_bug.cgi?id=759579), [https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961](https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961).