libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1008-1 | libxml2 security update |
Debian DSA |
DSA-3952-1 | libxml2 security update |
EUVD |
EUVD-2017-17989 | libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398. |
Ubuntu USN |
USN-3424-1 | libxml2 vulnerabilities |
Ubuntu USN |
USN-3424-2 | libxml2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:55:22.042Z
Reserved: 2017-05-18T00:00:00
Link: CVE-2017-9049
No data.
Status : Deferred
Published: 2017-05-18T06:29:00.467
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-9049
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN