Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-9251

Опубликовано: 04 апр. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 2.6
EPSS Низкий

Описание

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xmlsoft:libxml2:2.9.8:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01046
Низкий

5.3 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 3.5
redhat
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 5.3
debian
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is ...

CVSS3: 5.3
github
больше 3 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 5.3
fstec
почти 8 лет назад

Уязвимость функции xz_decomp библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01046
Низкий

5.3 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-835