Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7941

Опубликовано: 18 нояб. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

РелизСтатусПримечание
devel

not-affected

2.9.2+zdfsg1-4
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.5
precise

released

2.7.8.dfsg-5.1ubuntu4.12
trusty

released

2.9.1+dfsg1-3ubuntu4.5
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.5
upstream

released

2.9.2+really2.9.1+dfsg1-0.1
vivid

released

2.9.2+dfsg1-3ubuntu0.1
vivid/stable-phone-overlay

released

2.9.2+dfsg1-3ubuntu0.2
vivid/ubuntu-core

DNE

wily

not-affected

2.9.2+zdfsg1-4

Показывать по

EPSS

Процентиль: 72%
0.00736
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

nvd
почти 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

debian
почти 10 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allo ...

github
больше 3 лет назад

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

fstec
почти 10 лет назад

Уязвимость операционной системы Ubuntu, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00736
Низкий

4.3 Medium

CVSS2