CVE-2017-8872: Critical severity XMLSoft Libxml2 vulnerability
Published May 10, 2017
·Updated
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
Affected Software
1 affected component
XMLSoft Libxml2=2.9.4
Event History
May 10, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-8872?
CVE-2017-8872 has a severity rating that indicates it can lead to denial of service or information disclosure.
2
How do I fix CVE-2017-8872?
To mitigate CVE-2017-8872, update libxml2 to the latest version that addresses the vulnerability.
3
What types of attacks can CVE-2017-8872 facilitate?
CVE-2017-8872 can facilitate buffer over-read exploits and lead to potential information disclosure.
4
Which version of libxml2 is affected by CVE-2017-8872?
CVE-2017-8872 specifically affects libxml2 version 2.9.4.
5
How can CVE-2017-8872 impact applications using libxml2?
Applications using libxml2 version 2.9.4 may experience denial of service or leak sensitive information due to CVE-2017-8872.