libxml2 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2 to crash. This vulnerability exists because of an incomplete fix for CVE-2016-1839. References: http://seclists.org/oss-sec/2017/q2/258
Created libxml2 tracking bugs for this issue: Affects: fedora-all [bug 1452550]
Created mingw-libxml2 tracking bugs for this issue: Affects: fedora-all [bug 1452551]
Upstream patch: https://gitlab.gnome.org/GNOME/libxml2/commit/45752d2c3