First published: Wed May 10 2017(Updated: )
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libxml2 | =2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8872 has a severity rating that indicates it can lead to denial of service or information disclosure.
To mitigate CVE-2017-8872, update libxml2 to the latest version that addresses the vulnerability.
CVE-2017-8872 can facilitate buffer over-read exploits and lead to potential information disclosure.
CVE-2017-8872 specifically affects libxml2 version 2.9.4.
Applications using libxml2 version 2.9.4 may experience denial of service or leak sensitive information due to CVE-2017-8872.