parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 78316e9dfc24906dd474630928ed1d3c562b568e |