CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting
Configurations

Configuration 1 (hide)

cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:*

History

19 Mar 2026, 18:41

Type Values Removed Values Added
CPE cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:*
First Time Toddr xml\
Toddr
References () https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch - () https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch - Patch
References () https://github.com/cpan-authors/XML-Parser/issues/39 - () https://github.com/cpan-authors/XML-Parser/issues/39 - Issue Tracking
References () https://rt.cpan.org/Ticket/Display.html?id=19860 - () https://rt.cpan.org/Ticket/Display.html?id=19860 - Mailing List
References () http://www.openwall.com/lists/oss-security/2026/03/19/2 - () http://www.openwall.com/lists/oss-security/2026/03/19/2 - Mailing List, Patch, Third Party Advisory

19 Mar 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/19/2 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

19 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 12:16

Updated : 2026-03-19 18:41


NVD link : CVE-2006-10003

Mitre link : CVE-2006-10003

CVE.ORG link : CVE-2006-10003


JSON object : View

Products Affected

toddr

  • xml\
CWE
CWE-122

Heap-based Buffer Overflow

CWE-193

Off-by-one Error