Vulnerability Description
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Xmlsoft | Libxml2 | 2.9.3 |
| Debian | Debian Linux | 8.0 |
| Hp | Icewall Federation Agent | 3.0 |
| Hp | Icewall File Manager | 3.0 |
| Opensuse | Leap | 42.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/98567Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9597Issue Tracking
- http://www.securityfocus.com/bid/98567Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9597Issue Tracking
FAQ
What is CVE-2016-9597?
CVE-2016-9597 is a vulnerability with a CVSS score of 7.5 (HIGH). It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service atta...
How severe is CVE-2016-9597?
CVE-2016-9597 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9597?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Xmlsoft Libxml2, Debian Debian Linux, Hp Icewall Federation Agent, Hp Icewall File Manager.