Home
Packages
Vulnerabilities
Vendors
Report
Policy
Login
Signup
« List of all CVEs
CVE-2017-16932
Published:
11/23/2017
Last updated:
12/4/2025
Reserved:
11/23/2017
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
CNA assigner:
mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca)
Requested by:
n/a
Metrics
Version
Score
Severity
Vector String
3.1
7.5
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Opam packages affected (5)
bap-llvm
conf-gtksourceview
conf-gtksourceview3
conf-librsvg2
lablgtk3-gtkspell3
Products affected (2)
Product
Vendor
Version
n/a
n/a
<= 4.2.5.7
n/a
n/a
n/a
References (36)
https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
http://xmlsoft.org/news.html
https://usn.ubuntu.com/3739-1/
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
https://bugzilla.gnome.org/show_bug.cgi?id=759579
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
http://xmlsoft.org/news.html
https://usn.ubuntu.com/3739-1/
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
https://bugzilla.gnome.org/show_bug.cgi?id=759579
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
http://xmlsoft.org/news.html
https://usn.ubuntu.com/3739-1/
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
https://bugzilla.gnome.org/show_bug.cgi?id=759579
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html
https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html
http://xmlsoft.org/news.html
https://usn.ubuntu.com/3739-1/
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
https://bugzilla.gnome.org/show_bug.cgi?id=759579
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html