Buffer overflow in Libxml2 - CVE-2017-7376

 

Buffer overflow in Libxml2 - CVE-2017-7376

Published: February 19, 2018 / Updated: July 20, 2020


Vulnerability identifier: #VU31350
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7376
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.


Affected software

Libxml2

How to mitigate CVE-2017-7376

Install update from vendor's website.

Libxml2 - update to 2.9.5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins