Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8035

Опубликовано: 18 нояб. 2015
Источник: debian

Описание

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.9.3+dfsg1-1package
libxml2not-affectedsqueezepackage

Примечания

  • Upstream patch: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f0709e3ca8f8947f2d91ed34e92e38a4c23eae63 (v2.9.3)

  • You can use "xmllint --version" to verify if libxml2 is compiled with "Lzma" support.

  • sid's 2.9.2+zdfsg1-4 claims to have "Lzma" support but it's broken in fact...

  • so it barfs on the problematic file (parser error : Start tag expected,

  • '<' not found) even though it does not have the fix yet. The next upstream

  • release will fix this issue and will restore XZ support.

  • https://www.openwall.com/lists/oss-security/2015/11/02/2

Связанные уязвимости

ubuntu
около 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

redhat
больше 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

nvd
около 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

github
больше 3 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

CVSS3: 7.3
fstec
около 10 лет назад

Уязвимость функции xz_decomp библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании