ox is vulnerable to Stack-based Buffer Overflow
71
High Risk
This release hardens the ox XML/SAX C parser against stack and dynamic-stack buffer overflow conditions triggered by truncated/unterminated input. The fix adds correct EOS/NULL termination handling, safe pointer/index adjustments before error reporting, and a buffer shift-type correction to prevent overflow/underflow behavior in SAX buffering logic.
You are affected if you are using a version that falls within the vulnerable range.
ox is vulnerable to Stack-based Buffer Overflow in versions 0.0.1 - 2.14.25.
Upgrade the ox library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant