Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9251

Опубликовано: 03 апр. 2018
Источник: redhat
CVSS3: 3.5

Описание

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

Отчет

This issue did not affect the versions of libxml2 as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Not affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat JBoss Core Serviceslibxml2Not affected
Red Hat JBoss Web Server 3libxml2Not affected
Red Hat Enterprise Linux 8libxml2FixedRHSA-2020:182728.04.2020
Red Hat Enterprise Linux 8libxml2FixedRHSA-2020:182728.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1565318libxml2: infinite loop in xz_decomp function in xzlib.c

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 5.3
nvd
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 5.3
debian
почти 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is ...

CVSS3: 5.3
github
больше 3 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 5.3
fstec
почти 8 лет назад

Уязвимость функции xz_decomp библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

3.5 Low

CVSS3