CVE-2017-9048

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
18/05/2017
Last modified:
18/12/2025

Description

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*