CVE-2017-0663
HIGH7.8EPSS 0.89%libxml2 - security update
發布日:2017/6/14修改日:2026/4/28
描述
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.
受影響套件(3)
- Debian/libxml2from 0, < 2.9.4+dfsg1-3.1
- Debian/libxml2from 0, < 2.8.0+dfsg1-7+wheezy9
- Debian/libxml2from 0, < 2.9.1+dfsg1-5+deb8u5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |