Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7942

Опубликовано: 18 нояб. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

РелизСтатусПримечание
devel

released

2.9.2+zdfsg1-4ubuntu1
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.5
precise

released

2.7.8.dfsg-5.1ubuntu4.12
trusty

released

2.9.1+dfsg1-3ubuntu4.5
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.5
upstream

released

2.9.2+really2.9.1+dfsg1-0.1
vivid

released

2.9.2+dfsg1-3ubuntu0.1
vivid/stable-phone-overlay

released

2.9.2+dfsg1-3ubuntu0.2
vivid/ubuntu-core

DNE

wily

released

2.9.2+zdfsg1-4ubuntu0.1

Показывать по

EPSS

Процентиль: 91%
0.04737
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

nvd
больше 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

debian
больше 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does n ...

github
около 4 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

fstec
больше 10 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.04737
Низкий

6.8 Medium

CVSS2