Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8035

Опубликовано: 02 нояб. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.

Отчет

This issue did not affect the versions of libxml2 as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include support for LZMA compression support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Not affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat JBoss Enterprise Web Server 2libxml2Will not fix
Red Hat Ansible Tower 3.5 for RHEL 7ansible-tower-35/ansible-towerFixedRHBA-2020:153922.04.2020
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHBA-2020:154022.04.2020
Red Hat Enterprise Linux 7libxml2FixedRHSA-2020:119031.03.2020
Red Hat JBoss Web Server 3.0libxml2FixedRHSA-2016:108917.05.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-252
https://bugzilla.redhat.com/show_bug.cgi?id=1277146libxml2: DoS caused by incorrect error detection during XZ decompression

EPSS

Процентиль: 77%
0.01051
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

nvd
около 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

debian
около 10 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly d ...

github
больше 3 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

CVSS3: 7.3
fstec
около 10 лет назад

Уязвимость функции xz_decomp библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01051
Низкий

4.3 Medium

CVSS2