CVE-2016-3705: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- HP Icewall Federation Agent: version 3.0 only
- HP Icewall File Manager: version 3.0 only
- Opensuse Leap: version 42.1 only
- Xmlsoft LIBXML2: version 2.9.3 only
Published 2016-05-17. Last modified 2026-06-17.