CVE-2017-16931

CRITICAL9.8EPSS 1.4%

libxml2 - security update

發布日:2017/11/23修改日:2025/11/19
也稱為:ALPINE-CVE-2017-16931DEBIAN-CVE-2017-16931

描述

parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(2)