{"id":"CVE-2017-5969","details":"libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document.  NOTE: The maintainer states \"I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.","modified":"2026-08-07T14:53:27.153729Z","published":"2017-04-11T16:59:00.343Z","related":["SUSE-SU-2017:1670-1","SUSE-SU-2017:1813-1","openSUSE-SU-2024:11016-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/11/05/3"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/02/13/1"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96188"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201711-01"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=778519"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}]}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5969.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}],"source":"CPE_STRING"}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5969.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}