CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting
Configurations

Configuration 1 (hide)

cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:*

History

No history.

Information

Published : 2026-03-19 12:16

Updated : 2026-03-19 18:41


NVD link : CVE-2006-10003

Mitre link : CVE-2006-10003

CVE.ORG link : CVE-2006-10003


JSON object : View

Products Affected

toddr

  • xml\
CWE
CWE-122

Heap-based Buffer Overflow

CWE-193

Off-by-one Error