Medium severity4.7NVD Advisory· Published Apr 11, 2017· Updated May 13, 2026
CVE-2017-5969
CVE-2017-5969
Description
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.openwall.com/lists/oss-security/2016/11/05/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2017/02/13/1nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/96188nvdThird Party AdvisoryVDB Entry
- bugzilla.gnome.org/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/04/msg00004.htmlnvd
- security.gentoo.org/glsa/201711-01nvd
News mentions
0No linked articles in our index yet.