libxml2: Mishandling parameter-entity references (CVE-2017-16931)
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references
because the NEXTL macro
calls the xmlParserHandlePEReference function in the case of a ‘%’
character in a DTD name.
Fixed In Version:
libxml2 2.9.5
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-16931
Patch:
https://github.com/GNOME/libxml2/commit/e26630548e7d138d2c560844c43820b6767251e3
(from redmine: issue id 8396, created on 2018-01-12, closed on 2018-01-25)
- Relations:
- child #8397 (closed)
- child #8398 (closed)
- child #8399 (closed)