Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8806

Опубликовано: 26 янв. 2016
Источник: redhat
CVSS2: 4.3

Описание

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

Отчет

This flaw was found to be a duplicate of CVE-2016-1839. Please see https://access.redhat.com/security/cve/CVE-2016-1839 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Not affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat JBoss Enterprise Web Server 1libxml2Not affected

Показывать по

Дополнительная информация

Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1304636libxml2: heap-buffer overread in dict.c

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

CVSS3: 7.5
nvd
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

CVSS3: 7.5
debian
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service ...

CVSS3: 7.5
github
больше 7 лет назад

Denial of service or RCE from libxml2 and libxslt

fstec
почти 10 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS2

Уязвимость CVE-2015-8806