CVE-2017-7376
Summary
| CVE | CVE-2017-7376 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-19 19:29:00 UTC |
| Updated | 2019-05-17 15:15:00 UTC |
| Description | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1462216 – (CVE-2017-7376) CVE-2017-7376 libxml2: Incorrect limit used for port values |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| 51e0cb2e5ec18eaf6fb331bc573ff27b743898f4 - platform/external/libxml2 - Git at Google |
CONFIRM |
android.googlesource.com |
Patch, Third Party Advisory |
| Increase buffer space for port in HTTP redirect support (5dca9eea) · Commits · GNOME / libxml2 · GitLab |
CONFIRM |
git.gnome.org |
Patch, Third Party Advisory |
| Android Security Bulletin—June 2017 | Android Open Source Project |
CONFIRM |
source.android.com |
Third Party Advisory |
| Google Android Libraries Multiple Remote Code Execution Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Google Android Multiple Flaws Let Remote Users Deny Service, Obtain Potentially Sensitive Information, and Execute Arbitrary Code and Let Local Apps Gain Elevated Privileges - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-3952-1 libxml2 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 904877 Common Base Linux Mariner (CBL-Mariner) Security Update for gettext (12334)