EIP-2026-103967
PRE-CVElibxml2 2.6.x - 'XMLWriter::writeAttribute()' Memory Leak Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103967. PoCs published by Kees Cook.
AI-analyzed exploit summary This PHP script demonstrates a local information-disclosure vulnerability in the 'libxml2' library by crafting a malformed XML attribute that triggers a memory content leak. The exploit uses XMLWriter to generate an XML element with a specific Unicode character sequence that exploits the vulnerability.
Description
libxml2 2.6.x - 'XMLWriter::writeAttribute()' Memory Leak Information Disclosure
Exploits (1)
This PHP script demonstrates a local information-disclosure vulnerability in the 'libxml2' library by crafting a malformed XML attribute that triggers a memory content leak. The exploit uses XMLWriter to generate an XML element with a specific Unicode character sequence that exploits the vulnerability.