Oval Definition:oval:com.ubuntu.xenial:def:201814404000
Revision Date:2018-07-19Version:1
Title:CVE-2018-14404 on Ubuntu 16.04 LTS (xenial) - medium.
Description:A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-14404
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND The 'libxml2' package in xenial was vulnerable but has been fixed (note: '2.9.3+dfsg1-1ubuntu0.6').
  • BACK