Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2716

Опубликовано: 12 мая 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Отчет

This issue affects the version of expat package as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact, a future update may address this flaw. Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5expatWill not fix
Red Hat Enterprise Linux 6expatWill not fix
Red Hat Ansible Tower 3.5 for RHEL 7ansible-tower-35/ansible-towerFixedRHBA-2020:153922.04.2020
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHBA-2020:154022.04.2020
Red Hat Enterprise Linux 5firefoxFixedRHSA-2015:098812.05.2015
Red Hat Enterprise Linux 5thunderbirdFixedRHSA-2015:101218.05.2015
Red Hat Enterprise Linux 6firefoxFixedRHSA-2015:098812.05.2015
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2015:101218.05.2015
Red Hat Enterprise Linux 7firefoxFixedRHSA-2015:098812.05.2015
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2015:101218.05.2015

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=1220607expat: Integer overflow leading to buffer overflow in XML_GetBuffer()

EPSS

Процентиль: 90%
0.05699
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

nvd
больше 10 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

debian
больше 10 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Fire ...

github
больше 3 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

oracle-oval
больше 5 лет назад

ELSA-2020-1011: expat security update (MODERATE)

EPSS

Процентиль: 90%
0.05699
Низкий

6.8 Medium

CVSS2