CVE-2017-9049
Last modified
CVE-2017-9049 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. EPSS estimates a 4.63% chance of exploitation in the next 30 days.
Description
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | 2.9.4 |
References
- http://www.openwall.com/lists/oss-security/2017/05/15/1Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98601Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2017/05/15/1Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98601Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9049?
How severe is CVE-2017-9049?
How do I fix CVE-2017-9049?
Are you affected by CVE-2017-9049?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
