Описание
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.9.4+dfsg1-6.1ubuntu1.2 |
| devel | released | 2.9.4+dfsg1-7ubuntu1 |
| esm-infra-legacy/trusty | released | 2.9.1+dfsg1-3ubuntu4.13 |
| esm-infra/bionic | released | 2.9.4+dfsg1-6.1ubuntu1.2 |
| esm-infra/xenial | released | 2.9.3+dfsg1-1ubuntu0.6 |
| precise/esm | not-affected | code not present |
| trusty | released | 2.9.1+dfsg1-3ubuntu4.13 |
| trusty/esm | released | 2.9.1+dfsg1-3ubuntu4.13 |
| upstream | released | 2.9.9 |
| xenial | released | 2.9.3+dfsg1-1ubuntu0.6 |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to caus ...
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
Уязвимость библиотеки libxml2, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3