OracleVM 3.3 / 3.4 : libxml2 (OVMSA-2016-0087)

critical Nessus Plugin ID 91800
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 6.7


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Update doc/redhat.gif in tarball

- Add libxml2-oracle-enterprise.patch and update logos in tarball

- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)

- Bug 763071: Heap-buffer-overflow in xmlStrncat (CVE-2016-1834)

- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup (CVE-2016-1840)

- Bug 758588: Heap-based buffer overread in xmlParserPrintFileContextInternal (CVE-2016-1838)

- Bug 758605: Heap-based buffer overread in xmlDictAddString (CVE-2016-1839)

- Bug 759398: Heap use-after-free in xmlDictComputeFastKey (CVE-2016-1836)

- Fix inappropriate fetch of entities content (CVE-2016-4449)

- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)

- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)

- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)

- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)

- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)

- Avoid building recursive entities (CVE-2016-3627)

- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)

- More format string warnings with possible format string vulnerability (CVE-2016-4448)

- Fix large parse of file from memory (rhbz#862969)


Update the affected libxml2 / libxml2-python packages.

See Also

Plugin Details

Severity: Critical

ID: 91800

File Name: oraclevm_OVMSA-2016-0087.nasl

Version: 2.7

Type: local

Published: 6/24/2016

Updated: 1/4/2021

Dependencies: 12634

Risk Information

Risk Factor: Critical

VPR Score: 6.7

CVSS v2.0

Base Score: 10

Temporal Score: 7.8

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

CVSS v3.0

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:libxml2, p-cpe:/a:oracle:vm:libxml2-python, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/23/2016

Vulnerability Publication Date: 3/24/2016

Reference Information

CVE: CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, CVE-2016-1840, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447, CVE-2016-4448, CVE-2016-4449