#VU9689 Heap-based buffer over-read in Libxml2 - CVE-2017-9050
Published: December 19, 2017
Libxml2
Gnome Development Team
Description
The weakness exists in the xmlDictAddString function of XMLSoft libxml2 due to improper bounds checking in the dict.c code. A remote attacker can send a specially crafted request, trigger heap-based buffer over-read condition and cause the service to crash.
Successful exploitation of the vulnerability results in denial of service.