libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
References
Configurations
History
21 Nov 2024, 03:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2017/dsa-3952 - | |
References | () http://www.openwall.com/lists/oss-security/2017/05/15/1 - Exploit, Mailing List, Patch, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/98601 - Third Party Advisory, VDB Entry | |
References | () https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E - | |
References | () https://security.gentoo.org/glsa/201711-01 - |
07 Nov 2023, 02:50
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2017-05-18 06:29
Updated : 2024-11-21 03:35
NVD link : CVE-2017-9049
Mitre link : CVE-2017-9049
CVE.ORG link : CVE-2017-9049
JSON object : View
Products Affected
xmlsoft
- libxml2
CWE
CWE-125
Out-of-bounds Read