CVE-2017-9047
Publication date 18 May 2017
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is assigned strlen(buf). If the content->type is XML_ELEMENT_CONTENT_ELEMENT, then (i) the content->prefix is appended to buf (if it actually fits) whereupon (ii) content->name is written to the buffer. However, the check for whether the content->name actually fits also uses 'len' rather than the updated buffer length strlen(buf). This allows us to write about "size" many bytes beyond the allocated memory. This vulnerability causes programs that use libxml2, such as PHP, to crash.
Status
Package | Ubuntu Release | Status |
---|---|---|
libxml2 | ||
16.04 LTS xenial |
Fixed 2.9.3+dfsg1-1ubuntu0.3
|
|
14.04 LTS trusty |
Fixed 2.9.1+dfsg1-3ubuntu4.10
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3424-1
- libxml2 vulnerabilities
- 19 September 2017
- USN-3424-2
- libxml2 vulnerabilities
- 10 October 2017