Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2006-10003

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting

A flaw was found in XML::Parser, a Perl module for parsing XML. This vulnerability, an off-by-one heap buffer overflow, occurs when processing an XML file with very deep element nesting. A remote attacker could exploit this by providing a specially crafted XML file, potentially leading to memory corruption.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-XML-ParserWill not fix
Red Hat Enterprise Linux 10perl-XML-ParserFixedRHSA-2026:768013.04.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportperl-XML-ParserFixedRHSA-2026:911020.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportperl-XML-ParserFixedRHSA-2026:857816.04.2026
Red Hat Enterprise Linux 8perl-XML-ParserFixedRHSA-2026:768113.04.2026
Red Hat Enterprise Linux 8.2 Advanced Update Supportperl-XML-ParserFixedRHSA-2026:860916.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportperl-XML-ParserFixedRHSA-2026:860816.04.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onperl-XML-ParserFixedRHSA-2026:860816.04.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportperl-XML-ParserFixedRHSA-2026:861016.04.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceperl-XML-ParserFixedRHSA-2026:861016.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2448999perl-xml-parser: XML::Parser: Memory corruption via deeply nested XML files

EPSS

Процентиль: 42%
0.00548
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting

CVSS3: 9.8
nvd
4 месяца назад

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting

CVSS3: 8.6
msrc
4 месяца назад

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack

CVSS3: 9.8
debian
4 месяца назад

XML::Parser versions through 2.47 for Perl has an off-by-one heap buff ...

CVSS3: 9.8
github
4 месяца назад

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting

EPSS

Процентиль: 42%
0.00548
Низкий

8.8 High

CVSS3