Logo
vulnerabilityCVE-2006-10003
Name
CVE-2006-10003
Source
NVD ( link)Debian ( link)
Description
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libxml-parser-perl
Patched

Vulnerability Ratings#


9.8
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
2.46
Not Affected
yocto
scarthgap
2.47
Patched

Resolved with patches#


libxml-parser-perl (yocto:master)

#
Title
Author
Resolve
1
fix: off-by-one heap buffer overflow in st_serial_stack
Toddr Bot <toddbot@rinaldo.us>
CVE-2006-10003

libxml-parser-perl (yocto:scarthgap)

#
Title
Author
Resolve
1
fix: off-by-one heap buffer overflow in st_serial_stack
Toddr Bot <toddbot@rinaldo.us>
CVE-2006-10003