Oval Definition:oval:com.ubuntu.xenial:def:201790480000000
Revision Date:2017-05-18Version:1
Title:CVE-2017-9048 on Ubuntu 16.04 LTS (xenial) - medium.
Description:libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 < size. This vulnerability causes programs that use libxml2, such as PHP, to crash.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-9048
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND libxml2 package in xenial was vulnerable but has been fixed (note: '2.9.3+dfsg1-1ubuntu0.3').
  • BACK