First published: Thu May 18 2017(Updated: )
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
Credit: Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore Wei Lei Liu Yang - Nanyang Technological University in Singapore cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <11 | 11 |
Apple tvOS | <11 | 11 |
Apple watchOS | <4 | 4 |
Apple iTunes for Windows | <12.7 | 12.7 |
Apple iCloud for Windows | <7.0 | 7.0 |
Apple macOS High Sierra | <10.13 | 10.13 |
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
debian/libxml2 | <=2.9.4+dfsg1-2.2<=2.9.1+dfsg1-5 | 2.9.4+dfsg1-3.1 2.9.4+dfsg1-2.2+deb9u1 2.9.1+dfsg1-5+deb8u5 |
Xmlsoft Libxml2 | =2.9.4 | |
debian/libxml2 | 2.9.4+dfsg1-7+deb10u4 2.9.4+dfsg1-7+deb10u6 2.9.10+dfsg-6.7+deb11u4 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2017-9049 is a vulnerability in the libxml2 library that could cause programs to crash.
CVE-2017-9049 affects various versions of Apple tvOS, iOS, libxml2 on Debian, macOS High Sierra, iTunes for Windows, watchOS, iCloud for Windows, and other versions of libxml2 on Debian.
CVE-2017-9049 has a severity score of 7.5, which is considered high.
To fix CVE-2017-9049, you should update to the latest version of the affected software or apply the recommended patches.
You can find more information about CVE-2017-9049 on the Apple support website and the Bugzilla page.