CVE Vulnerabilities

CVE-2017-5969

NULL Pointer Dereference

Published: Apr 11, 2017 | Modified: Apr 20, 2025
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Libxml2Xmlsoft2.9.4 (including)2.9.4 (including)
Libxml2Ubuntuartful*
Libxml2Ubuntudevel*
Libxml2Ubuntuesm-infra-legacy/trusty*
Libxml2Ubuntuesm-infra/xenial*
Libxml2Ubuntuprecise*
Libxml2Ubuntuprecise/esm*
Libxml2Ubuntutrusty*
Libxml2Ubuntutrusty/esm*
Libxml2Ubuntuupstream*
Libxml2Ubuntuvivid/stable-phone-overlay*
Libxml2Ubuntuxenial*
Libxml2Ubuntuyakkety*
Libxml2Ubuntuzesty*

Potential Mitigations

References