PT-2026-26286 · Unknown+4 · Xml Parser+4

CVE-2006-10003

·

Publicado

2006-01-01

·

Atualizado

2026-08-13

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XML::Parser versions through 2.47
Description The software contains a heap buffer overflow in the st serial stack function. This occurs when parsing XML files with deeply nested elements. Specifically, when stackptr equals stacksize - 1, the stack is not expanded, and a new value is written outside the allocated buffer at the stacksize location.
Recommendations Update to a version of XML::Parser later than 2.47.

Correção

DoS

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:7679
ALSA-2026:7680
ALSA-2026:7681
AZL-80196
BDU:2026-12814
CVE-2006-10003
MGASA-2026-0063
OPENSUSE-SU-2026:10527-1
OPENSUSE-SU-2026:20459-1
RHSA-2026:7679
RHSA-2026:7680
RHSA-2026:7681
RHSA-2026:8577
RHSA-2026:8578
RHSA-2026:8608
RHSA-2026:8609
RHSA-2026:8610
RHSA-2026:9110
RHSA-2026:9246
RHSA-2026:9258
RHSA-2026:9259
RHSA-2026:9605
SUSE-SU-2026:1152-1
SUSE-SU-2026:1153-1
SUSE-SU-2026:20993-1
USN-8174-1

Produtos afetados

Linuxmint
Red Os
Rocky Linux
Ubuntu
Xml Parser