MEDIUM · 5.5

CVE-2016-1838

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to ...

Vulnerability Description

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
DebianDebian Linux8.0
AppleIphone Os< 9.3.2
AppleMac Os X< 10.11.5
AppleTvos< 9.2.1
AppleWatchos< 2.2.1
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Eus7.2
RedhatEnterprise Linux Server Tus7.2
RedhatEnterprise Linux Workstation6.0
McafeeWeb Gateway>= 7.5.0.0, <= 7.5.2.10
XmlsoftLibxml2<= 2.9.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1838?

CVE-2016-1838 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to ...

How severe is CVE-2016-1838?

CVE-2016-1838 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-1838?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Debian Debian Linux, Apple Iphone Os, Apple Mac Os X, Apple Tvos.