← Back

CVE-2016-4472

nvd nist
Published: Jun 30, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.

Affected (8)

Show all products
Libexpat
1 product
Ubuntu Linux
1 product
Policy Auditor
1 product
Python
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.1.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.04
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.5.1
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Python
From 2.7.0 to 2.7.15
From 3.3.0 to 3.3.7
From 3.4.0 to 3.4.7
From 3.5.0 to 3.5.4
From 3.6.0 to 3.6.2

References (14)

Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.