CVE-2017-18926
published 2020-11-06CVE-2017-18926: raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML…
PriorityP336high7.1CVSS 3.1
AVNACLPRNUIRSUCNILAH
EPSS
3.12%
86.5th percentile
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | raptor2 | < raptor2 2.0.14-1.1 (bookworm) | raptor2 2.0.14-1.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| librdf | raptor_rdf_syntax_library | — | — |
| librdf | raptor_rdf_syntax_library | >= 0 < 1.4.21-11ubuntu0.1~esm1 | 1.4.21-11ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
raptor vulnerabilities
osv·2025-11-10·CVSS 7.1
CVE-2017-18926 [HIGH] raptor vulnerabilities
raptor vulnerabilities
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could use this issue to
cause Raptor to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2017-18926)
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
GHSA
GHSA-p2vv-g8rx-7jqj: raptor_xml_writer_start_element_common in raptor_xml_writer
ghsa_unreviewed·2022-05-24
CVE-2017-18926 [HIGH] CWE-787 GHSA-p2vv-g8rx-7jqj: raptor_xml_writer_start_element_common in raptor_xml_writer
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
OSV
CVE-2017-18926: raptor_xml_writer_start_element_common in raptor_xml_writer
osv·2020-11-06·CVSS 7.1
CVE-2017-18926 [HIGH] CVE-2017-18926: raptor_xml_writer_start_element_common in raptor_xml_writer
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Ubuntu
Raptor vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 7.1
CVE-2017-18926 [HIGH] Raptor vulnerabilities
Title: Raptor vulnerabilities
Summary: Several security issues were fixed in Raptor.
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could use this issue to
cause Raptor to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2017-18926)
Hanno Böck discovered that Raptor incorrectly handled memory operations
when processing certain input files. An attacker could possibly use this
issue to cause Raptor to crash, resulting in a denial of service.
(CVE-2020-25713)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Raptor vulnerability
vendor_ubuntu·2020-11-11
CVE-2017-18926 Raptor vulnerability
Title: Raptor vulnerability
Summary: raptor2 could be made to crash or run programs as your login if it opened a
specially crafted file.
Hanno Böck discovered that Raptor incorrectly handled certain memory
operations. If a user were tricked into opening a specially crafted
document in an application linked against Raptor, an attacker could
cause the application to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications which
use Raptor, such as LibreOffice, to make all the necessary changes.
Red Hat
raptor: heap-based buffer overflows due to an error in calculating the maximum nspace declarations for the XML writer
vendor_redhat·2017-06-07·CVSS 7.1
CVE-2017-18926 [HIGH] CWE-122 raptor: heap-based buffer overflows due to an error in calculating the maximum nspace declarations for the XML writer
raptor: heap-based buffer overflows due to an error in calculating the maximum nspace declarations for the XML writer
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Statement: LibreOffice as shipped with Red Hat Enterprise Linux 8 is notaffected by this flaw as the version of raptor used in LibreOffice already has the patch.
Package: libreoffice (Red Hat Enterprise Linux 6) - Out of support scope
Package: raptor (Red Hat Enterprise Linux 6) - Out of support scope
Package: libreoffice (Red Hat Enterprise Linux 7) - Out of support scope
Package: raptor2 (Red Hat Enterprise Linux 7) - O
Debian
CVE-2017-18926: raptor2 - raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Synt...
vendor_debian·2017·CVSS 7.1
CVE-2017-18926 [HIGH] CVE-2017-18926: raptor2 - raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Synt...
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
Scope: local
bookworm: resolved (fixed in 2.0.14-1.1)
bullseye: resolved (fixed in 2.0.14-1.1)
forky: resolved (fixed in 2.0.14-1.1)
sid: resolved (fixed in 2.0.14-1.1)
trixie: resolved (fixed in 2.0.14-1.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/11/13/1http://www.openwall.com/lists/oss-security/2020/11/13/2http://www.openwall.com/lists/oss-security/2020/11/14/2http://www.openwall.com/lists/oss-security/2020/11/16/2http://www.openwall.com/lists/oss-security/2020/11/16/3https://github.com/LibreOffice/core/blob/master/external/redland/raptor/0001-Calcualte-max-nspace-declarations-correctly-for-XML-.patch.1https://lists.debian.org/debian-lts-announce/2020/11/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD67AVORGQXORPWNYYUHCH6YPPT6CI4O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVHFYQDMVEBICIL4DBAGRRLPUR4QYWMV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDZRNM45VPTQF2BKRWG4YRCHJGQ2L7NS/https://www.debian.org/security/2020/dsa-4785https://www.openwall.com/lists/oss-security/2017/06/07/1http://www.openwall.com/lists/oss-security/2020/11/13/1http://www.openwall.com/lists/oss-security/2020/11/13/2http://www.openwall.com/lists/oss-security/2020/11/14/2http://www.openwall.com/lists/oss-security/2020/11/16/2http://www.openwall.com/lists/oss-security/2020/11/16/3https://github.com/LibreOffice/core/blob/master/external/redland/raptor/0001-Calcualte-max-nspace-declarations-correctly-for-XML-.patch.1https://lists.debian.org/debian-lts-announce/2020/11/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD67AVORGQXORPWNYYUHCH6YPPT6CI4O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVHFYQDMVEBICIL4DBAGRRLPUR4QYWMV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDZRNM45VPTQF2BKRWG4YRCHJGQ2L7NS/https://www.debian.org/security/2020/dsa-4785https://www.openwall.com/lists/oss-security/2017/06/07/1
2020-11-06
Published