Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1819

Опубликовано: 14 апр. 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

A denial of service flaw was found in the way the libxml2 library parsed certain XML files. An attacker could provide a specially crafted XML file that, when parsed by an application using libxml2, could cause that application to use an excessive amount of memory.

Отчет

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libxml2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Will not fix
Red Hat Enterprise Linux 6libxml2FixedRHSA-2015:141920.07.2015
Red Hat Enterprise Linux 7libxml2FixedRHSA-2015:255007.12.2015

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1211278libxml2: denial of service processing a crafted XML document

EPSS

Процентиль: 85%
0.02464
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

nvd
около 10 лет назад

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

debian
около 10 лет назад

The xmlreader in libxml allows remote attackers to cause a denial of s ...

github
около 7 лет назад

Nokogiri vulnerable to libxml XML Entity Expansion

oracle-oval
около 10 лет назад

ELSA-2015-1419: libxml2 security and bug fix update (LOW)

EPSS

Процентиль: 85%
0.02464
Низкий

2.6 Low

CVSS2