CVE-2017-9050

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
18/05/2017
Last modified:
17/12/2025

Description

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*