CVE-2017-9050
published 2017-05-18CVE-2017-9050: libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | itunes_12.7_for_windows | — | — |
| apple | macos_high_sierra | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| apple | tvos | — | — |
| apple | watchos_4 | — | — |
| debian | libxml2 | < libxml2 2.9.4+dfsg1-3.1 (bookworm) | libxml2 2.9.4+dfsg1-3.1 (bookworm) |
| nokogiri | nokogiri | >= 0 < 1.8.1 | 1.8.1 |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-3.1 | 2.9.4+dfsg1-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-3.1 | 2.9.4+dfsg1-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-3.1 | 2.9.4+dfsg1-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-3.1 | 2.9.4+dfsg1-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.10 | 2.9.1+dfsg1-3ubuntu4.10 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.3 | 2.9.3+dfsg1-1ubuntu0.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa5.5MEDIUM
osv7.8HIGH