Cross-site scripting in Libxml2 - CVE-2016-3709

 

Cross-site scripting in Libxml2 - CVE-2016-3709

Published: August 5, 2022 / Updated: August 29, 2022


Vulnerability identifier: #VU66123
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-3709
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Libxml2
IBM Cloud Pak for Watson AIOps
cflinuxfs3
IBM supplied MQ Advanced container images
ObjectScale
PowerStore T
OpenManage Network Integration (OMNI)
Enterprise SONiC
Robotic Process Automation for Cloud Pak
Oracle Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Ubuntu
openEuler
Self Node Remediation Operator
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Virtualization
Migration Toolkit for Runtimes
IBM MQ Operator
Migration Toolkit for Virtualization
Ansible Automation Platform
IBM Watson Assistant for IBM Cloud Pak for Data
OpenShift Logging
Netcool Operations Insight
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
SmartFabric Storage Software
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
libxml2-devel
libxml2-doc
libxml2-2
libxml2-2-32bit
libxml2-2-debuginfo
libxml2-2-debuginfo-32bit
libxml2-debugsource
libxml2-tools
libxml2-tools-debuginfo
python-libxml2-debuginfo
python-libxml2
python-libxml2-debugsource
libxml2 (Red Hat package)
libxml2-2-32bit-debuginfo
libxml2-devel-32bit
python3-libxml2-python
python2-libxml2-python-debuginfo
python2-libxml2-python
python3-libxml2-python-debuginfo
python-libxml2-python-debugsource
libxml2-help
python3-libxml2
python2-libxml2
libxml2-debuginfo
libxml2
Voice Gateway
Cloud Pak for Security (CP4S)
RecoverPoint for VMs
Dell EMC VxRail Appliance

How to mitigate CVE-2016-3709

Install update from vendor's website.

cflinuxfs3 - update to 0.314.0
Self Node Remediation Operator - update to 0.5.1
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.26.0, 1.27.0
SmartFabric Storage Software - update to 1.4.3
Migration Toolkit for Containers - update to 1.7.6
OpenShift Service Mesh - update to 2.3.1
Migration Toolkit for Virtualization - update to 2.4.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
OpenShift Virtualization - addressed in versions 4.11.1, 4.11.6, 4.11.7, 4.12.0, 4.12.8
Red Hat OpenShift Container Platform - update to 4.11.49
OpenShift Logging - addressed in versions 5.3.14, 5.4.8, 5.5.5
IBM supplied MQ Advanced container images - update to 9.3.0.1-r3
Voice Gateway - addressed in versions 1.0.8.1, 1.0.8.2, 1.0.8.5
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.3
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.7, 2.9.10+dfsg-5ubuntu0.20.04.4
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.7, 2.9.10+dfsg-5ubuntu0.20.04.4
libxml2-devel - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-doc - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-2 - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-2-32bit - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-2-debuginfo-32bit - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1
libxml2-debugsource - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-tools - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.59.2, 2.9.4-46.65.1, 2.9.7-150000.3.51.1
python-libxml2-debuginfo - addressed in versions 2.9.4-46.59.3, 2.9.4-46.65.1
python-libxml2 - addressed in versions 2.9.4-46.59.3, 2.9.4-46.65.1
python-libxml2-debugsource - addressed in versions 2.9.4-46.59.3, 2.9.4-46.65.1
libxml2 (Red Hat package) - addressed in versions 2.9.7-13.el8_6.2, 2.9.7-15.el8
libxml2-2-32bit-debuginfo - update to 2.9.7-150000.3.51.1
libxml2-devel-32bit - update to 2.9.7-150000.3.51.1
python3-libxml2-python - update to 2.9.7-150000.3.51.1
python2-libxml2-python-debuginfo - update to 2.9.7-150000.3.51.1
python2-libxml2-python - update to 2.9.7-150000.3.51.1
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.51.1
python-libxml2-python-debugsource - update to 2.9.7-150000.3.51.1
libxml2-help - addressed in versions 2.9.10-29, 2.9.10-31
libxml2-debugsource - addressed in versions 2.9.10-29, 2.9.10-31
libxml2-devel - addressed in versions 2.9.10-29, 2.9.10-31
python3-libxml2 - addressed in versions 2.9.10-29, 2.9.10-31
python2-libxml2 - addressed in versions 2.9.10-29, 2.9.10-31
libxml2-debuginfo - addressed in versions 2.9.10-29, 2.9.10-31
libxml2 - addressed in versions 2.9.10-29, 2.9.10-31
IBM Cloud Transformation Advisor - update to 3.4.0
PowerStore T - update to 3.5.0.1-2083289
OpenManage Network Integration (OMNI) - update to 3.7
Enterprise SONiC - update to 4.4.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 7.0.411
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1

External References

Related Security Bulletins