Description
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-691-1 | libxml2 security update |
Debian DSA |
DSA-3744-1 | libxml2 security update |
Github GHSA |
GHSA-fr52-4hqw-p27f | Nokogiri does not forbid namespace nodes in XPointer ranges |
Ubuntu USN |
USN-3235-1 | libxml2 vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T00:39:25.880Z
Reserved: 2016-05-11T00:00:00.000Z
Link: CVE-2016-4658
No data.
Status : Modified
Published: 2016-09-25T10:59:02.343
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-4658
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN