CVE-2016-9597

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 30 Jul 2018, 14:00
Last modified:06 Aug 2024, 02:59

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.0 (nvd)
EPSS Score
1.22% LOW
1% probability -0.11%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2018, 14:00
Published
Vulnerability first disclosed
06 Aug 2024, 02:59
Last Modified
Vulnerability information updated

Description

It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.22% Percentile: 79%

Techniques & Countermeasures

  • CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.10 | 16.04

  • debiandebian_linux

    8.0

  • hpicewall_federation_agent

    3.0

  • hpicewall_file_manager

    3.0

  • opensuseleap

    42.1

  • red hatlibxml2

    all

  • xmlsoftlibxml2

    2.9.3

References (2)