VDB

DEBIAN-CVE-2017-9049

DEBIAN-CVE-2017-9049 PUBLISHED CVSS 7.5 HIGH

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:14libxml20, 0, 0
Debian:12libxml20, 0, 0
Debian:11libxml20, 0, 0
Debian:13libxml20, 0, 0

Timeline

  • May 18, 2017 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›