Back

HIGH

chromium-browser: heap overflow in libxml2

Published Feb 7, 2018

Description

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

Affected products

Remediation

Red Hat statement

This issue does not affect the libxml library shipped with Red Hat Enterprise Linux because the affected code xmlMemoryStrdup() is a debug-only function that should never be called in production builds. The only exception is xmllint when invoked with --maxmem. The same issue applies to the other two affected functions namely xmlMallocLoc and xmlReallocLoc.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Feb 7, 2018
Updated Dec 3, 2025
Reserved Jan 2, 2017
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 17, 2017