libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 < size. This vulnerability causes programs that use libxml2, such as PHP, to crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml2 | Aug 23, 2017 | May 18, 2017 |
| Freebsd | — | Upgrade libxml2 | Dec 14, 2017 | Dec 13, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | May 18, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Dec 4, 2019 | May 18, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-python | Dec 18, 2019 | May 18, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-python | Nov 19, 2019 | May 18, 2017 |
| Oracle Solaris | — | Upgrade library/python/libxml2-27 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/libxml2 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3 | Jan 19, 2021 | May 18, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2017 |
| Suse | — | Upgrade python2-libxml2-pythonUpgrade libxml2-pythonUpgrade libxml2-2-32bitUpgrade python-libxml2Upgrade libxml2-develUpgrade libxml2-2Upgrade libxml2Upgrade libxml2-toolsUpgrade libxml2-x86Upgrade libxml2-docUpgrade python3-libxml2-pythonUpgrade sles12sp2-docker-imageUpgrade libxml2-32bitUpgrade sles12sp1-docker-imageUpgrade libxml2-devel-32bitUpgrade sles12-docker-image | May 31, 2017 | May 18, 2017 |
| Ubuntu | — | Upgrade libxml2 | Sep 19, 2017 | May 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub