CVE-2016-4658

Description

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
19.344

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-4658 are fixed in Ruby-nokogiri 1.7.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.4Windows
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.9.0Windows
GNOME XML library (USN-3235-1) libxml2_2.9.4+dfsg1-2ubuntu0.1_i386.debLinux
GNOME XML library (USN-3235-1) libxml2_2.9.4+dfsg1-2ubuntu0.1_amd64.debLinux
GNOME XML library (USN-3235-1) libxml2_2.7.8.dfsg-5.1ubuntu4.17_i386.debLinux
GNOME XML library (USN-3235-1) libxml2_2.7.8.dfsg-5.1ubuntu4.17_amd64.debLinux
libxml2 security update(DSA-3744-1) libxml2_2.9.1+dfsg1-5+deb8u4_i386.debLinux
libxml2 security update(DSA-3744-1) libxml2_2.9.1+dfsg1-5+deb8u4_kfreebsd-i386.debLinux
libxml2 security update(DSA-3744-1) libxml2_2.9.1+dfsg1-5+deb8u4_kfreebsd-amd64.debLinux
(RHSA-2021:3810) libxml2 security update libxml2-2.9.1-6.el7_9.6.i686.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-2.9.1-6.el7_9.6.x86_64.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-devel-2.9.1-6.el7_9.6.i686.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-devel-2.9.1-6.el7_9.6.x86_64.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-python-2.9.1-6.el7_9.6.x86_64.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-static-2.9.1-6.el7_9.6.i686.rpmLinux
(RHSA-2021:3810) libxml2 security update libxml2-static-2.9.1-6.el7_9.6.x86_64.rpmLinux
Libxml2 update (ELSA-2021-3810) libxml2-2.9.1-6.0.3.el7_9.6.i686.rpmLinux
Libxml2 update (ELSA-2021-3810) libxml2-2.9.1-6.0.3.el7_9.6.x86_64.rpmLinux
Libxml2-devel update (ELSA-2021-3810) libxml2-devel-2.9.1-6.0.3.el7_9.6.i686.rpmLinux
Libxml2-devel update (ELSA-2021-3810) libxml2-devel-2.9.1-6.0.3.el7_9.6.x86_64.rpmLinux
Libxml2-python update (ELSA-2021-3810) libxml2-python-2.9.1-6.0.3.el7_9.6.x86_64.rpmLinux
Libxml2-static update (ELSA-2021-3810) libxml2-static-2.9.1-6.0.3.el7_9.6.i686.rpmLinux
Libxml2-static update (ELSA-2021-3810) libxml2-static-2.9.1-6.0.3.el7_9.6.x86_64.rpmLinux
(RHSA-2021:3810)Moderate: security update libxml2-debuginfo-2.9.1-6.el7_9.6.i686.rpmLinux
(RHSA-2021:3810)Moderate: security update libxml2-debuginfo-2.9.1-6.el7_9.6.x86_64.rpmLinux
Vulnerabilities CVE-2016-4658 are fixed in Ruby-nokogiri for Linux 1.7.1Linux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2016-4658)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234