Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-7942

Опубликовано: 18 нояб. 2015
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

РелизСтатусПримечание
devel

released

2.9.2+zdfsg1-4ubuntu1
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.5
precise

released

2.7.8.dfsg-5.1ubuntu4.12
trusty

released

2.9.1+dfsg1-3ubuntu4.5
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.5
upstream

released

2.9.2+really2.9.1+dfsg1-0.1
vivid

released

2.9.2+dfsg1-3ubuntu0.1
vivid/stable-phone-overlay

released

2.9.2+dfsg1-3ubuntu0.2
vivid/ubuntu-core

DNE

wily

released

2.9.2+zdfsg1-4ubuntu0.1

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

redhat
около 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

nvd
почти 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

debian
почти 10 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does n ...

github
больше 3 лет назад

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

fstec
почти 10 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

6.8 Medium

CVSS2