7.5
CVE-2016-3705
- EPSS 5.1%
- Veröffentlicht 17.05.2016 14:08:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Hp ≫ Icewall Federation Agent Version 3.0
Hp ≫ Icewall File Manager Version 3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.1% | 0.913 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://rhn.redhat.com/errata/RHSA-2016-2957.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
https://security.gentoo.org/glsa/201701-37
https://www.tenable.com/security/tns-2016-18
http://www.ubuntu.com/usn/USN-2994-1
https://www.debian.org/security/2016/dsa-3593
https://access.redhat.com/errata/RHSA-2016:1292
https://kc.mcafee.com/corporate/index?page=content&id=SB10170
http://lists.opensuse.org/opensuse-updates/2016-05/msg00055.html
http://lists.opensuse.org/opensuse-updates/2016-05/msg00127.html
http://seclists.org/fulldisclosure/2016/May/10
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157239
http://www.securityfocus.com/bid/89854
https://bugzilla.gnome.org/show_bug.cgi?id=765207