CVE-2016-3627 CVE-2016-3705: libxml2: stack overflow in xml validator (parser)

Posted by Simon Lees on May 03

Hi
This is a disclosure of the following issue that was raised a week ago
on the distro’s mailing list. Both bugs on the gnome bugtracker are
currently private and should be made public now. The two attached
patches are based off the 2.9.3 libxml2 release.

A couple of weeks back while working on a related bug [CVE-2016-3627] I
discovered a specially created xml file is capable of triggering a stack
overflow before libxml2 can detect its a…

Leave a Reply