CVE-2017-5130
Description
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.762
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update for Google Chrome (62.0.3202.62) | Windows |
| Update for Google Chrome x64 (62.0.3202.62) | Windows |
| Multiple vulnerabilities fixed in iCloud (7.17.0.13) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.4.76) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.0.166) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.1.14) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.2.58) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.4.80) | Windows |
| Multiple vulnerabilities fixed in Apple Application Installer for iTunes (12.7.5.9) | Windows |
| Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.0.166) | Windows |
| Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.1.14) | Windows |
| Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.2.58) | Windows |
| Multiple vulnerabilities fixed in Update for Apple iTunes X64 (12.7.2.60) | Windows |
| Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.3.46) | Windows |
| Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.4.76) | Windows |
| Multiple vulnerabilities fixed in Updates for Apple iTunes (X64) (12.7.4.80) | Windows |
| Multiple vulnerabilities fixed in Apple iTunes (X64) (12.7.5.9) | Windows |
| Multiple vulnerabilities are affected in Oracle HTTP Server 11.1.1.9.0 | Windows |
| Multiple vulnerabilities are fixed in Update for Google Chrome For Mac (62.0.3202.62) | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 - Reboot Automatically | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 Combo Update - Reboot Automatically | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.5 - Reboot Automatically | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 - Reboot Automatically | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 Combo Update - Reboot Automatically | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 Combo Update | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo Update | Mac |
| Multiple vulnerabilities are fixed in macOS High Sierra 10.13.1 | Mac |
| Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13.1 | Mac |
| Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13 | Mac |
| SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-2.7.6-0.77.10.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-32bit-2.7.6-0.77.10.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-doc-2.7.6-0.77.10.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0395-1(SUSE Linux Enterprise Server 11-SP4 ) libxml2-python-2.7.6-0.77.10.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-32bit-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-debuginfo-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-2-debuginfo-32bit-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-debugsource-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Server 12-SP2 ) libxml2-doc-2.9.4-46.12.1.noarch.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-tools-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) libxml2-tools-debuginfo-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-debuginfo-2.9.4-46.12.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0401-1(SUSE Linux Enterprise Desktop 12-SP2 ) python-libxml2-debugsource-2.9.4-46.12.1.x86_64.rpm | Linux |
| Update for Google Chrome (62.0.3202.62) (For Ubuntu) | Linux |
| Update for Google Chrome (62.0.3202.62) (For Debian) | Linux |
| Update for Google Chrome (62.0.3202.62) (For Centos) | Linux |
| Update for Google Chrome (62.0.3202.62) (For RedHat) | Linux |
| Update for Google Chrome (62.0.3202.62) (For Suse) | Linux |
| Out-of-bounds Write Vulnerability (CVE-2017-5130) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-306542 | Update for Google Chrome (62.0.3202.62) |
| PATCH-306543 | Update for Google Chrome x64 (62.0.3202.62) |
| PATCH-312688 | iCloud (7.17.0.13) |
| PATCH-306388 | Update for Apple iTunes X64 (12.7.0.166) |
| PATCH-306603 | Update for Apple iTunes X64 (12.7.1.14) |
| PATCH-306795 | Update for Apple iTunes X64 (12.7.2.58) |
| PATCH-306828 | Update for Apple iTunes X64 (12.7.2.60) |
| PATCH-307024 | Updates for Apple iTunes (X64) (12.7.3.46) |
| PATCH-307343 | Updates for Apple iTunes (X64) (12.7.4.76) |
| PATCH-307418 | Updates for Apple iTunes (X64) (12.7.4.80) |
| PATCH-307618 | Apple iTunes (X64) (12.7.5.9) |
| PATCH-609673 | Google Chrome for Mac (132.0.6834.83, 132.0.6834.84) |
| PATCH-601562 | macOS High Sierra 10.13.6 - Reboot Automatically |
| PATCH-601563 | macOS High Sierra 10.13.6 Combo Update - Reboot Automatically |
| PATCH-601563 | macOS High Sierra 10.13.6 Combo Update - Reboot Automatically |
| PATCH-601562 | macOS High Sierra 10.13.6 - Reboot Automatically |
| PATCH-601563 | macOS High Sierra 10.13.6 Combo Update - Reboot Automatically |
| PATCH-601562 | macOS High Sierra 10.13.6 - Reboot Automatically |
| PATCH-601563 | macOS High Sierra 10.13.6 Combo Update - Reboot Automatically |
| PATCH-601562 | macOS High Sierra 10.13.6 - Reboot Automatically |
| PATCH-601563 | macOS High Sierra 10.13.6 Combo Update - Reboot Automatically |
| PATCH-601562 | macOS High Sierra 10.13.6 - Reboot Automatically |
| PATCH-601312 | Security Update 2017-001 macOS High Sierra v10.13.1 |
| PATCH-601345 | Security Update 2017-001 macOS High Sierra v10.13 |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234