QID 375544

Date Published: 2021-05-12

QID 375544: Libxml2 Arbitrary Code Execution Vulnerability

The libxml2 library is a development toolbox providing the implementation of various XML standards.

xpointer.c in libxml2 before 2.9.5 does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service.

Affected Products:

Red Hat Enterprise Linux for x86_64 8 x86_64
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5

QID Detection logic: Authenticated
This qid checks for vulnerable libxml2 package from the list of package installed.

Successful exploitation may allow remote attackers to execute arbitrary code or cause a denial of service

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    No patch is available for the issue. Please refer to Red Hat security advisory cve-2016-4658 to obtain more information.
    Vendor References

    CVEs related to QID 375544

    Software Advisories
    Advisory ID Software Component Link