Loop with Unreachable Exit Condition ('Infinite Loop')
Affecting libxml2 package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2017-16932
- CWE
- CWE-835
- Snyk ID
- SNYK-DEBIAN9-LIBXML2-429485
- Disclosed
- 23 Nov, 2017
- Published
- 23 Nov, 2017