CVE-2017-7376: Debian Linux
Critical severity, CVSS 9.8. EPSS: 23.3% chance of exploitation in the next 30 days.
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Google Android: version 4.4.4 only; version 5.0.2 only; version 5.1.1 only; version 6.0 only; version 6.0.1 only; version 7.0 only; …
- Xmlsoft LIBXML2: before 2.9.5 (fixed in 2.9.5)
Published 2018-02-19. Last modified 2026-06-17.