[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254492

 
 

909

 
 

198541

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1301 --- libxml2

ID: oval:org.secpod.oval:def:1700218Date: (C)2019-10-07   (M)2023-12-20
Class: PATCHFamily: unix




xpointer.c in libxml2 before 2.9.5 does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted XML document. parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a #039;%#039; character in a DTD name

Platform:
Amazon Linux 2
Product:
libxml2
Reference:
ALAS2-2019-1301
CVE-2017-16931
CVE-2016-4658
CVE    2
CVE-2016-4658
CVE-2017-16931

© SecPod Technologies