CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting
Configurations

Configuration 1 (hide)

cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:*

History

04 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/04/msg00002.html -
Summary
  • (es) Las versiones de XML::Parser hasta la 2.47 para Perl tienen un desbordamiento de búfer de montón por un error de uno en st_serial_stack. En el caso (stackptr == stacksize - 1), la pila NO se expandirá. Luego, el nuevo valor se escribirá en la ubicación (++stackptr), que es igual a stacksize y, por lo tanto, cae justo fuera del búfer asignado. El error se puede observar al analizar un archivo XML con anidamiento de elementos muy profundo.

19 Mar 2026, 18:41

Type Values Removed Values Added
CPE cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:*
First Time Toddr xml\
Toddr
References () https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch - () https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch - Patch
References () https://github.com/cpan-authors/XML-Parser/issues/39 - () https://github.com/cpan-authors/XML-Parser/issues/39 - Issue Tracking
References () https://rt.cpan.org/Ticket/Display.html?id=19860 - () https://rt.cpan.org/Ticket/Display.html?id=19860 - Mailing List
References () http://www.openwall.com/lists/oss-security/2026/03/19/2 - () http://www.openwall.com/lists/oss-security/2026/03/19/2 - Mailing List, Patch, Third Party Advisory

19 Mar 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/19/2 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

19 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 12:16

Updated : 2026-04-04 09:16


NVD link : CVE-2006-10003

Mitre link : CVE-2006-10003

CVE.ORG link : CVE-2006-10003


JSON object : View

Products Affected

toddr

  • xml\
CWE
CWE-122

Heap-based Buffer Overflow

CWE-193

Off-by-one Error