CVE-2011-1944

critical
Published 2011-09-02 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-35810 remote linux verified
Chris Evans ยท 2011-05-31

libxmlInvalid 2.7.x - XPath Multiple Memory Corruption Vulnerabilities

Source code queued for fetch โ€” refresh in a moment.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.7.8.dfsg-3
sid Fixed 2.7.8.dfsg-3
forky Fixed 2.7.8.dfsg-3
bullseye Fixed 2.7.8.dfsg-3
bookworm Fixed 2.7.8.dfsg-3

Application impact

VendorProductVersionsFixed
xmlsoftlibxml22.6.7
xmlsoftlibxml22.6.8
xmlsoftlibxml22.6.9
xmlsoftlibxml22.6.11
xmlsoftlibxml22.6.12
xmlsoftlibxml22.6.13
xmlsoftlibxml22.6.14
xmlsoftlibxml22.6.16
xmlsoftlibxml22.6.17
xmlsoftlibxml22.6.18
xmlsoftlibxml22.6.20
xmlsoftlibxml22.6.22
xmlsoftlibxml22.6.26
xmlsoftlibxml22.6.27
xmlsoftlibxml22.6.30
xmlsoftlibxml22.6.32
xmlsoftlibxml22.7.0
xmlsoftlibxml22.7.1
xmlsoftlibxml22.7.2
xmlsoftlibxml22.7.3
xmlsoftlibxml22.7.4
xmlsoftlibxml22.7.5
xmlsoftlibxml22.7.6
xmlsoftlibxml22.7.7
xmlsoftlibxml22.7.8
xmlsoftlibxml{"endIncluding":"1.8.16"}
xmlsoftlibxml1.5.0
xmlsoftlibxml1.6.0
xmlsoftlibxml1.6.1
xmlsoftlibxml1.6.2
xmlsoftlibxml1.7.0
xmlsoftlibxml1.7.1
xmlsoftlibxml1.7.2
xmlsoftlibxml1.7.3
xmlsoftlibxml1.7.4
xmlsoftlibxml1.8.0
xmlsoftlibxml1.8.1
xmlsoftlibxml1.8.2
xmlsoftlibxml1.8.3
xmlsoftlibxml1.8.4
xmlsoftlibxml1.8.5
xmlsoftlibxml1.8.6
xmlsoftlibxml1.8.7
xmlsoftlibxml1.8.8
xmlsoftlibxml1.8.9
xmlsoftlibxml1.8.10
xmlsoftlibxml1.8.11
xmlsoftlibxml1.8.12
xmlsoftlibxml1.8.13
xmlsoftlibxml1.8.14
xmlsoftlibxml1.8.15
xmlsoftlibxml22.6.0
xmlsoftlibxml22.6.1
xmlsoftlibxml22.6.2
xmlsoftlibxml22.6.3
xmlsoftlibxml22.6.4
xmlsoftlibxml22.6.5
xmlsoftlibxml22.6.6

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.