Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
L
libxml2
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 69
    • Issues 69
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 9
    • Merge Requests 9
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Incidents
    • Environments
  • Packages & Registries
    • Packages & Registries
    • Container Registry
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • GNOME
  • libxml2
  • Issues
  • #190

Closed
Open
Opened Oct 05, 2020 by WOOSEUNGHOON@WOOSEUNGHOON

Version inconsistency in CVE-2016-3705

Hi,

We discovered that the CVE-2016-3705 vulnerability, which was found to only affect libxml2 2.9.3, affects libxml2 2.9.2.

We utilized the same PoC and reproducer in https://bugzilla.gnome.org/show_bug.cgi?id=765207

This is a minor issue, but NVD mentions only 2.9.3 is affected by CVE-2016-3705, and we are worried that it will adversely affect developers who are using 2.9.2.

Please reflect on this after confirmation. Thank you.

Edited Oct 05, 2020 by WOOSEUNGHOON
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: GNOME/libxml2#190