ZeroHour

CVE-2017-9050

PoC
CVSS 3.1
7.5 high
EPSS
5%p91
Published
()
Modified
Description

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.

Vendors
xmlsoft
Products
libxml2
Weakness
CWE-125, CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.