CVE-2017-5130 describes an integer overflow vulnerability in libxml2, specifically within the xmlmemory.c component, affecting versions prior to 2.9.5. This flaw, present in products like Google Chrome and Debian Linux, could allow a remote attacker to trigger heap corruption by enticing a user to open a specially crafted XML file. With a CVSS score of 8.8 (High), this vulnerability poses a significant risk, enabling potential high impact to confidentiality, integrity, and availability with low attack complexity and no authentication required. While there are no known active exploits, Metasploit modules, or ExploitDB entries, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 62.0.3202.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
< 2.9.5CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.