[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-8317Date: (C)2015-12-21   (M)2024-04-19


The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1034243
BID-77681
BID-91826
APPLE-SA-2016-07-18-1
APPLE-SA-2016-07-18-2
APPLE-SA-2016-07-18-3
APPLE-SA-2016-07-18-4
APPLE-SA-2016-07-18-6
DSA-3430
HPSBGN03537
RHSA-2015:2549
RHSA-2016:1089
USN-2834-1
http://www.openwall.com/lists/oss-security/2015/11/21/1
http://www.openwall.com/lists/oss-security/2015/11/22/3
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://blog.fuzzing-project.org/28-Libxml2-Several-out-of-bounds-reads.html
https://bugzilla.gnome.org/show_bug.cgi?id=751603
https://bugzilla.gnome.org/show_bug.cgi?id=751631
https://bugzilla.redhat.com/show_bug.cgi?id=1281930
https://git.gnome.org/browse/libxml2/commit/?id=709a952110e98621c9b78c4f26462a9d8333102e
https://git.gnome.org/browse/libxml2/commit/?id=9aa37588ee78a06ca1379a9d9356eab16686099c
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172
https://support.apple.com/HT206899
https://support.apple.com/HT206901
https://support.apple.com/HT206902
https://support.apple.com/HT206903
https://support.apple.com/HT206904
https://support.apple.com/HT206905
openSUSE-SU-2015:2372
openSUSE-SU-2016:0106

CPE    13
cpe:/o:redhat:enterprise_linux_hpc_node:6.0
cpe:/o:debian:debian_linux:7.0
cpe:/o:debian:debian_linux:8.0
cpe:/a:xmlsoft:libxml2:2.9.2
...
CWE    1
CWE-119
OVAL    17
oval:org.secpod.oval:def:204176
oval:org.secpod.oval:def:203780
oval:org.secpod.oval:def:52645
oval:org.secpod.oval:def:501720
...

© SecPod Technologies