PT-2017-3261 · Xmlsoft+3 · Libxml2+3

Published

2017-05-15

·

Updated

2021-06-29

·

CVE-2017-9050

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libxml2 version 20904-GITv2.9.4-16-g0741801
Description The issue is caused by a heap-based buffer over-read in the xmlDictAddString function in dict.c. This can lead to a crash in programs that use libxml2, such as PHP. The vulnerability exists due to an incomplete fix for a previous issue. It may allow a remote attacker to cause a denial of service.
Recommendations For libxml2 version 20904-GITv2.9.4-16-g0741801, consider disabling the xmlDictAddString function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1924
ALT-PU-2019-3079
BDU:2018-00017
CVE-2017-9050
DLA-1008-1
DSA-3952-1
GHSA-8C56-CPMW-89X7
MGASA-2018-0048
SUSE-SU-2017:1454-1
SUSE-SU-2017:1538-1
SUSE-SU-2017:1557-1
SUSE-SU-2017:1587-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3424-1
USN-3424-2

Affected Products

Alt Linux
Suse
Ubuntu
Libxml2