libxml2 CVE-2017-8872 Denial of Service Vulnerability
BID:101557
Info
libxml2 CVE-2017-8872 Denial of Service Vulnerability
| Bugtraq ID: | 101557 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-8872 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2017 12:00AM |
| Updated: | Oct 10 2017 12:00AM |
| Credit: | deng yi |
| Vulnerable: |
XMLSoft Libxml2 2.9.4 Redhat RHEV-M for Servers 0 Redhat JBoss Web Server (JWS) 3.0 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 IBM Streams 4.2.1.2 IBM Streams 4.2.1.1 IBM InfoSphere Streams 4.0.1 IBM InfoSphere Streams 3.2.1 IBM InfoSphere Streams 4.1.1.4 IBM InfoSphere Streams 4.1.1.1 IBM InfoSphere Streams 4.1.1.0 IBM InfoSphere Streams 4.1 IBM InfoSphere Streams 4.0.1.4 IBM InfoSphere Streams 4.0.1.1 IBM InfoSphere Streams 4.0.1.0 IBM InfoSphere Streams 3.2.1.6 IBM InfoSphere Streams 3.2.1.5 IBM InfoSphere Streams 3.2.1.4 IBM InfoSphere Streams 3.2.1.3 IBM InfoSphere Streams 3.2.1.2 IBM InfoSphere Streams 3.2 IBM InfoSphere Streams 3.1.0.8 IBM InfoSphere Streams 3.1.0.7 IBM InfoSphere Streams 3.1.0.6 IBM InfoSphere Streams 3.1.0.5 IBM InfoSphere Streams 3.1.0.4 IBM InfoSphere Streams 3.1.0.3 IBM InfoSphere Streams 3.1.0.1 IBM InfoSphere Streams 3.0.0.6 IBM InfoSphere Streams 3.0.0.5 IBM InfoSphere Streams 3.0.0.4 IBM InfoSphere Streams 3.0.0.1 IBM InfoSphere Streams 3.0 |
| Not Vulnerable: |
IBM InfoSphere Streams 4.2.1.3 IBM InfoSphere Streams 4.1.1.5 IBM InfoSphere Streams 4.0.1.5 |
Discussion
libxml2 CVE-2017-8872 Denial of Service Vulnerability
libxml2 is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to obtain sensitive information or cause denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
Libxml2 2.9.4 is vulnerable; other versions may also be affected.
libxml2 is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to obtain sensitive information or cause denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
Libxml2 2.9.4 is vulnerable; other versions may also be affected.
Exploit / POC
libxml2 CVE-2017-8872 Denial of Service Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.