Memory corruption in Libxml2 - CVE-2017-9047

 

Memory corruption in Libxml2 - CVE-2017-9047

Published: December 19, 2017 / Updated: April 28, 2025


Vulnerability identifier: #VU9687
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9047
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the xmlSnprintfElementContent function of XMLSoft libxml2 due to improper memory handling by the valid.c source code. A remote attacker can send a specially crafted XML file, trigger memory corruption and cause the service to crash.

Successful exploitation of the vulnerability results in denial of service.


Affected software

Libxml2
Gentoo Linux
Anolis OS
openEuler
Fedora
IBM Concert Software
IBM Observability with Instana
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Business Automation
App Connect Enterprise Certified Container
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
Rapid Infrastructure Automation
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
Business Automation Insights
Integrated Management Module II (IMM2)
System Storage DS8900F
QRadar Suite
watsonx.data
IBM Edge Application Manager
Traffix SDC
IBM Qradar SIEM
IBM Security Guardium
IBM API Connect
libxml2
libxml2-static
libxml2-python
libxml2-devel
python3-libxml2
libxml2-help
libxml2-debugsource
libxml2-debuginfo
libxml2-doc
IBM CICS TX Advanced
IBM DS8000 Hardware Management Console

How to mitigate CVE-2017-9047

Install update from vendor's website.

IBM Concert Software - update to 2.0.0
IBM Observability with Instana - update to 1.0.297
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
watsonx.data - update to 2.2
Guardium Data Security Center (GDSC) - addressed in versions 3.7.2, 3.8.5
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF04
IBM Security Guardium - update to 10.0p400
IBM API Connect - update to 10.0.8.5
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Integrated Management Module II (IMM2) - addressed in versions 1AOO80G-6.40, 1AOO80G-6.40_bc
libxml2 - addressed in versions 2.9.1-6.0.2, 2.9.7-19.0.1, 2.11.5-11
libxml2-static - addressed in versions 2.9.1-6.0.2, 2.11.5-11
libxml2-python - update to 2.9.1-6.0.2
libxml2-devel - addressed in versions 2.9.1-6.0.2, 2.9.7-19.0.1, 2.11.5-11
libxml2 - addressed in versions 2.9.7-1.fc26, 2.9.7-1.fc27
python3-libxml2 - addressed in versions 2.9.7-19.0.1, 2.11.5-11
libxml2-help - update to 2.9.14-15
python3-libxml2 - update to 2.9.14-15
libxml2-devel - update to 2.9.14-15
libxml2-debugsource - update to 2.9.14-15
libxml2-debuginfo - update to 2.9.14-15
libxml2 - update to 2.9.14-15
libxml2-doc - update to 2.11.5-11
App Connect Enterprise Certified Container - addressed in versions 5.0.1, 6.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
Traffix SDC - update to 5.2.0 CF8
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
IBM DS8000 Hardware Management Console - update to 10.10.106.0 R10.1
System Storage DS8900F - update to 89.44.4.0 R9.4 SP4

External References

Related Security Bulletins