---
cve: "CVE-2016-4658"
severity: "LOW"
cvss: 3.1
epss: "8.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2016-09-25 10:59:02"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T05:21:08+02:00"
---

# CVE-2016-4658

> 3.1 LOW

## Beschreibung

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

## Patch verfügbar (OSV)

- 2960178fe8f9fe690b7f8c1c49093ff54bb56934 (Commit)
- 2960178fe8f9fe690b7f8c1c49093ff54bb56934 (Commit)

## Referenzen

- <https://support.apple.com/HT207141>
- <http://www.securitytracker.com/id/1036858>
- <http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html>
- <http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html>
- <http://lists.apple.com/archives/security-announce/2016/Sep/msg00010.html>
- <http://lists.apple.com/archives/security-announce/2016/Sep/msg00011.html>
- <http://www.securityfocus.com/bid/93054>
- <https://support.apple.com/HT207170>
- <https://security.gentoo.org/glsa/201701-37>
- <https://support.apple.com/HT207142>
- <https://support.apple.com/HT207143>
- <http://www.securitytracker.com/id/1038623>
- <https://git.gnome.org/browse/libxml2/commit/?id=c1d1f7121194036608bf555f08d3062a36fd344b>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-4658) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
