{"schema_version":"1.9.0","id":"CVE-2017-9050","published":"2017-05-18T06:29:00.497Z","modified":"2026-09-01T08:06:44.159990Z","aliases":["GHSA-8c56-cpmw-89x7"],"related":["SUSE-SU-2017:1454-1","SUSE-SU-2017:1538-1","SUSE-SU-2017:1557-1","SUSE-SU-2017:1587-1","SUSE-SU-2017:2699-1","SUSE-SU-2017:2700-1"],"details":"libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}],"source":"CPE_STRING"}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9050.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"}],"database_specific":{"cpe":"cpe:2.3:a:xmlsoft:libxml2:2.9.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.4"},{"last_affected":"2.9.4"}],"source":"CPE_STRING"}}],"versions":["2.9.4","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9050.json"}}],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3952"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98568"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201711-01"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/05/15/1"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}