Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7942

Опубликовано: 18 нояб. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

РелизСтатусПримечание
devel

released

2.9.2+zdfsg1-4ubuntu1
esm-infra-legacy/trusty

not-affected

2.9.1+dfsg1-3ubuntu4.5
precise

released

2.7.8.dfsg-5.1ubuntu4.12
trusty

released

2.9.1+dfsg1-3ubuntu4.5
trusty/esm

not-affected

2.9.1+dfsg1-3ubuntu4.5
upstream

released

2.9.2+really2.9.1+dfsg1-0.1
vivid

released

2.9.2+dfsg1-3ubuntu0.1
vivid/stable-phone-overlay

released

2.9.2+dfsg1-3ubuntu0.2
vivid/ubuntu-core

DNE

wily

released

2.9.2+zdfsg1-4ubuntu0.1

Показывать по

EPSS

Процентиль: 78%
0.01157
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

nvd
почти 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

debian
почти 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does n ...

github
больше 3 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

fstec
почти 10 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 78%
0.01157
Низкий

6.8 Medium

CVSS2