Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8317

Опубликовано: 15 дек. 2015
Источник: debian
EPSS Низкий

Описание

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.9.2+zdfsg1-4package

Примечания

  • https://bugzilla.gnome.org/show_bug.cgi?id=751631

  • https://gitlab.gnome.org/GNOME/libxml2/-/commit/709a952110e98621c9b78c4f26462a9d8333102e

  • https://bugzilla.gnome.org/show_bug.cgi?id=751603

  • https://gitlab.gnome.org/GNOME/libxml2/-/commit/9aa37588ee78a06ca1379a9d9356eab16686099c

EPSS

Процентиль: 51%
0.00275
Низкий

Связанные уязвимости

ubuntu
больше 9 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

redhat
около 10 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

nvd
больше 9 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

github
больше 3 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

fstec
больше 9 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 51%
0.00275
Низкий