{"id":"CVE-2017-9048","details":"libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 \u003c size. This vulnerability causes programs that use libxml2, such as PHP, to crash.","modified":"2026-08-31T08:25:26.558985Z","published":"2017-05-18T06:29:00.433Z","related":["SUSE-SU-2017:1454-1","SUSE-SU-2017:1538-1","SUSE-SU-2017:1557-1","SUSE-SU-2017:1587-1","SUSE-SU-2017:2699-1","SUSE-SU-2017:2700-1","openSUSE-SU-2024:11016-1"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3952"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98556"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201711-01"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/05/15/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}]}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9048.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}],"source":"CPE_STRING"}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9048.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}