Back

HIGH

libxml2: Stack-based buffer overflow in function xmlSnprintfElementContent

Published May 18, 2017

Description

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 < size. This vulnerability causes programs that use libxml2, such as PHP, to crash.

Affected products

Remediation

Red Hat statement

This vulnerability exists in the DTD validation functionality of libxml2. Applications that do not attempt to validate untrusted documents are not impacted.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 18, 2017
Updated Dec 18, 2025
Reserved May 18, 2017
CISA Vulnrichment
Updated Dec 18, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 15, 2017