Описание
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | released | 2.9.4+dfsg1-6.1ubuntu1.2 |
| devel | released | 2.9.4+dfsg1-7ubuntu1 |
| esm-infra-legacy/trusty | released | 2.9.1+dfsg1-3ubuntu4.13 |
| esm-infra/bionic | released | 2.9.4+dfsg1-6.1ubuntu1.2 |
| esm-infra/xenial | released | 2.9.3+dfsg1-1ubuntu0.6 |
| precise/esm | not-affected | code not present |
| trusty | released | 2.9.1+dfsg1-3ubuntu4.13 |
| trusty/esm | released | 2.9.1+dfsg1-3ubuntu4.13 |
| upstream | released | 2.9.6 |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote ...
Уязвимость функции xz_head компонента xzlib.c библиотеки Libxml2, связанная с недостатком механизма распределения ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3