VDB

CVE-2017-9048

CVE-2017-9048 PUBLISHED

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 < size. This vulnerability causes programs that use libxml2, such as PHP, to crash.

EPSS 0.60% · 69.9th percentile

Risk Scores

EPSS Score
0.60%
69.9th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxml2*, 2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4
Ubuntu:16.04:LTSlibxml22.9.2+zdfsg1-4, 2.9.2+zdfsg1-4ubuntu2, 2.9.2+zdfsg1-4ubuntu3

Exploit Intelligence

…and 20 more exploits

Timeline

  • May 18, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Jun 29, 2021 CVE Updated
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›