VulnerabilityModified
CVE-2017-9049
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c.
HIGH 7.5EPSS 4.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.63% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- xmlsoft/libxml2
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3952
- http://www.openwall.com/lists/oss-security/2017/05/15/1Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98601Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.gentoo.org/glsa/201711-01
- http://www.debian.org/security/2017/dsa-3952
- http://www.openwall.com/lists/oss-security/2017/05/15/1Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98601Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://security.gentoo.org/glsa/201711-01
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.