CVE-2016-4447
CVE-2016-4447
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttps://access.redhat.com/errata/RHSA-2016:1292https://git.gnome.org/browse/libxml2/commit/?id=00906759053986b8079985644172085f74331f83https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05194709https://kc.mcafee.com/corporate/index?page=content&id=SB10170https://support.apple.com/HT206899https://support.apple.com/HT206901