Parameter Entity Reference Vulnerability in libxml2 by GNOME
CVE-2017-16931

9.8CRITICAL

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
23 November 2017

What is CVE-2017-16931?

A vulnerability exists in libxml2 that arises from improper handling of parameter-entity references. Specifically, the issue occurs in the parser.c file before version 2.9.5, where the NEXTL macro incorrectly calls the xmlParserHandlePEReference function for '%' characters in a Document Type Definition (DTD) name. This flaw may have significant implications for applications that rely on xml parsing, potentially leading to unauthorized access or manipulation of data.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.