cve/2016/CVE-2016-3627.md
2024-06-18 02:51:15 +02:00

925 B

CVE-2016-3627

Description

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.

POC

Reference

Github

No PoCs found on GitHub currently.