PT-2017-3260 · Php+4 · Php+4

Published

2017-05-15

·

Updated

2025-12-18

·

CVE-2017-9049

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libxml2 version 20904-GITv2.9.4-16-g0741801
Description The issue is caused by a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This can cause programs that use libxml2, such as PHP, to crash. The problem exists due to an incomplete fix for a previous bug. Exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations For libxml2 version 20904-GITv2.9.4-16-g0741801, as a temporary workaround, consider disabling the xmlDictComputeFastKey function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1924
ALT-PU-2019-3079
BDU:2018-00016
CVE-2017-9049
DLA-1008-1
DSA-3952-1
MGASA-2018-0048
OPENSUSE-SU-2024:11016-1
SUSE-SU-2017:1454-1
SUSE-SU-2017:1538-1
SUSE-SU-2017:1557-1
SUSE-SU-2017:1587-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3424-1
USN-3424-2

Affected Products

Alt Linux
Php
Suse
Ubuntu
Libxml2