CVE-2017-5969

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*

History

07 Nov 2023, 02:49

Type Values Removed Values Added
Summary ** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser." libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

Information

Published : 2017-04-11 16:59

Updated : 2024-08-05 16:15


NVD link : CVE-2017-5969

Mitre link : CVE-2017-5969


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-476

NULL Pointer Dereference