CVE-2017-0663
Description
A remote code execution vulnerability in libxml2 allows attackers to execute arbitrary code via a specially crafted file in Android applications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A remote code execution vulnerability in libxml2 allows attackers to execute arbitrary code via a specially crafted file in Android applications.
Vulnerability
The vulnerability resides in the libxml2 library, which is used for parsing XML in Android. A specially crafted XML file can trigger a memory corruption error. This affects Android versions 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, and 7.1.2 [1].
Exploitation
An attacker can exploit this vulnerability by convincing a user to process a malicious XML document, typically via a web page or application that uses libxml2. No authentication is required, and the attack can be performed remotely [2].
Impact
Successful exploitation allows arbitrary code execution within the context of an unprivileged process. This could lead to disclosure of sensitive data, modification of files, or further compromise of the device [1][2].
Mitigation
Google released patches in the June 2017 Android Security Bulletin [1]. For non-Android systems, the Gentoo advisory recommends upgrading to libxml2 version 2.9.4-r3 or later [2].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
24cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*
- (no CPE)range: Android-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2
- osv-coords15 versionspkg:rpm/opensuse/libxml2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/python-libxml2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/python-libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/python-libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/python-libxml2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2
< 2.9.12-1.2+ 14 more
- (no CPE)range: < 2.9.12-1.2
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.7.6-0.76.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.7.6-0.76.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.7.6-0.76.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.7.6-0.76.4
- (no CPE)range: < 2.7.6-0.76.4
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.9.4-42.1
- (no CPE)range: < 2.9.4-42.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/98877nvdThird Party AdvisoryVDB Entry
- source.android.com/security/bulletin/2017-06-01nvdVendor Advisory
- www.debian.org/security/2017/dsa-3952nvd
- www.securitytracker.com/id/1038623nvd
- lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Envd
- lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Envd
- security.gentoo.org/glsa/201711-01nvd
News mentions
0No linked articles in our index yet.