CVE-2017-5130

Description

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.762

Associated Vulnerability

VulnerabilityOS Platform
Update for Google Chrome (62.0.3202.62)Windows
Update for Google Chrome x64 (62.0.3202.62)Windows
Multiple vulnerabilities fixed in iCloud (7.17.0.13)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.4.76)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.0.166)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.1.14)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.2.58)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.4.80)Windows
Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.5.9)Windows
Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.0.166)Windows
Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.1.14)Windows
Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.2.58)Windows
Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.2.60)Windows
Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.3.46)Windows
Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.4.76)Windows
Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.4.80)Windows
Multiple vulnerabilities fixed in Apple iTunes (X64) (12.7.5.9)Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 11.1.1.9.0Windows
Multiple vulnerabilities are fixed in Update for Google Chrome For Mac (62.0.3202.62)Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.5 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13Mac
SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-2.7.6-0.77.10.1.x86_64.rpmLinux
SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-32bit-2.7.6-0.77.10.1.x86_64.rpmLinux
SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-doc-2.7.6-0.77.10.1.x86_64.rpmLinux
SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-python-2.7.6-0.77.10.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-32bit-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-debuginfo-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-debuginfo-32bit-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-debugsource-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Server 12-SP2 ) libxml2-doc-2.9.4-46.12.1.noarch.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-tools-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-tools-debuginfo-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-debuginfo-2.9.4-46.12.1.x86_64.rpmLinux
SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-debugsource-2.9.4-46.12.1.x86_64.rpmLinux
Update for Google Chrome (62.0.3202.62) (For Ubuntu)Linux
Update for Google Chrome (62.0.3202.62) (For Debian)Linux
Update for Google Chrome (62.0.3202.62) (For Centos)Linux
Update for Google Chrome (62.0.3202.62) (For RedHat)Linux
Update for Google Chrome (62.0.3202.62) (For Suse)Linux
Out-of-bounds Write Vulnerability (CVE-2017-5130)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-306542Update for Google Chrome (62.0.3202.62)
PATCH-306543Update for Google Chrome x64 (62.0.3202.62)
PATCH-312688iCloud (7.17.0.13)
PATCH-306388Update for Apple iTunes X64 (12.7.0.166)
PATCH-306603Update for Apple iTunes X64 (12.7.1.14)
PATCH-306795Update for Apple iTunes X64 (12.7.2.58)
PATCH-306828Update for Apple iTunes X64 (12.7.2.60)
PATCH-307024Updates for Apple iTunes (X64) (12.7.3.46)
PATCH-307343Updates for Apple iTunes (X64) (12.7.4.76)
PATCH-307418Updates for Apple iTunes (X64) (12.7.4.80)
PATCH-307618Apple iTunes (X64) (12.7.5.9)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601312Security Update 2017-001 macOS High Sierra v10.13.1
PATCH-601345Security Update 2017-001 macOS High Sierra v10.13

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234