CVE-2025-6170: Libxml2: stack buffer overflow in xmllint interactive shell command handling
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6170?
CVE-2025-6170 has a high severity rating due to the potential for a crash and exploitation of the xmllint command-line tool.
How do I fix CVE-2025-6170?
To fix CVE-2025-6170, update to the latest version of the xmllint tool where this vulnerability has been patched.
What impact does CVE-2025-6170 have on my system?
CVE-2025-6170 may allow attackers to execute arbitrary code or cause a denial of service by crashing the xmllint tool.
Who is affected by CVE-2025-6170?
CVE-2025-6170 affects any user or application that utilizes the xmllint command-line tool for parsing XML files.
Is CVE-2025-6170 a remote vulnerability?
CVE-2025-6170 is not classified as a remote vulnerability since it requires a local command execution to trigger the flaw.