Libxml2 xmlStringGetNodeList Function Denial of Service Vulnerability (CVE-2016-3627)
Libxml2 xmlStringGetNodeList Function Denial of Service Vulnerability (CVE-2016-3627)
Release date:
Updated on:
Affected Systems:
Libxml libxml2 <= 2.9.3
Description:
CVE (CAN) ID: CVE-2016-3627
Libxml2 is an XML Parser and markup tool set.
In libxml2 2.9.3 and earlier versions, when the tree. c/xmlStringGetNodeList function is used in the recovery mode, an independent context attacker can create a denial of service by constructing an xml document.
<* Source: libxml2
*>
Suggestion:
Vendor patch:
Libxml
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.xmlsoft.org/index.html
Refer:
Http://seclists.org/fulldisclosure/2016/May/10
Http://www.openwall.com/lists/oss-security/2016/03/21/3
Http://lists.opensuse.org/opensuse-updates/2016-05/msg00055.html
Http://www.openwall.com/lists/oss-security/2016/03/21/2
This article permanently updates the link address: