CVE-2015-1819
published 2015-08-14CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.34%
92.9th percentile
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.2+really2.9.1+dfsg1-0.1 (bookworm) | libxml2 2.9.2+really2.9.1+dfsg1-0.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| nokogiri | nokogiri | >= 1.6.6.0 < 1.6.6.4 | 1.6.6.4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux | <= 5.0 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.2+really2.9.1+dfsg1-0.1 | 2.9.2+really2.9.1+dfsg1-0.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.2+really2.9.1+dfsg1-0.1 | 2.9.2+really2.9.1+dfsg1-0.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.2+really2.9.1+dfsg1-0.1 | 2.9.2+really2.9.1+dfsg1-0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-11-16·CVSS 5.0
CVE-2015-1819 [MEDIUM] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
Florian Weimer discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause resource consumption,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)
Michal Zalewski discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)
Kostya Serebryany di
Red Hat
libxml2: denial of service processing a crafted XML document
vendor_redhat·2015-04-14·CVSS 5.0
CVE-2015-1819 [MEDIUM] libxml2: denial of service processing a crafted XML document
libxml2: denial of service processing a crafted XML document
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
A denial of service flaw was found in the way the libxml2 library parsed certain XML files. An attacker could provide a specially crafted XML file that, when parsed by an application using libxml2, could cause that application to use an excessive amount of memory.
Statement: Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libxml2.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-1819: libxml2 - The xmlreader in libxml allows remote attackers to cause a denial of service (me...
vendor_debian·2015·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: libxml2 - The xmlreader in libxml allows remote attackers to cause a denial of service (me...
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Scope: local
bookworm: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
bullseye: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
forky: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
sid: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
trixie: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
Apple
CVE-2015-5312: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-1819: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-1819
Component: CVE-2015-1819
Apple
CVE-2015-1819: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-1819
Component: CVE-2015-1819
Apple
CVE-2015-1819: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-1819
Component: CVE-2015-1819
Apple
CVE-2015-5312: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-5312: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-5312: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-1819: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-1819
Component: CVE-2015-1819
GHSA
Nokogiri vulnerable to libxml XML Entity Expansion
ghsa·2018-08-08
CVE-2015-1819 [MEDIUM] CWE-776 Nokogiri vulnerable to libxml XML Entity Expansion
Nokogiri vulnerable to libxml XML Entity Expansion
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
OSV
Nokogiri vulnerable to libxml XML Entity Expansion
osv·2018-08-08
CVE-2015-1819 [MEDIUM] Nokogiri vulnerable to libxml XML Entity Expansion
Nokogiri vulnerable to libxml XML Entity Expansion
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
OSV
libxml2 vulnerabilities
osv·2015-11-16·CVSS 5.0
CVE-2015-1819 [MEDIUM] libxml2 vulnerabilities
libxml2 vulnerabilities
Florian Weimer discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause resource consumption,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)
Michal Zalewski discovered that libxml2 incorrectly handled certain XML
data. If a user or automated system were tricked into opening a specially
crafted document, an attacker could possibly cause libxml2 to crash,
resulting in a denial of service. This issue only affected
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)
Kostya Serebryany discovered that libxml2 incorrectly handled certain XML
data. If a
OSV
CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expan
osv·2015-08-14·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expan
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1819 libxml2: denial of service processing a crafted XML document
bugzilla·2015-04-13·CVSS 5.0
CVE-2015-1819 [MEDIUM] CVE-2015-1819 libxml2: denial of service processing a crafted XML document
CVE-2015-1819 libxml2: denial of service processing a crafted XML document
Florian Weimer from Red Hat reported an issue against libxml2, where a parser which uses libxml2 chokes on a crafted XML document, allocating gigabytes of data.
This is a fine line between API misuse and an libxml2 bug.
Daniel Veillard have a fix for this issue already.
Discussion:
Patch updstream
https://git.gnome.org/browse/libxml2/commit/?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9
Daniel
---
(In reply to Daniel Veillard from comment #3)
> Patch updstream
>
> https://git.gnome.org/browse/libxml2/commit/
> ?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9
>
> Daniel
Could you please let me know the version in which the bug has been fixed and provide the URL for downloading the same ?
---
Acknowledgements:
N
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172710.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172943.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1419.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75570http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2812-1http://xmlsoft.org/news.htmlhttps://git.gnome.org/browse/libxml2/commit/?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9https://security.gentoo.org/glsa/201507-08https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172710.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172943.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1419.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75570http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2812-1http://xmlsoft.org/news.htmlhttps://git.gnome.org/browse/libxml2/commit/?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9https://security.gentoo.org/glsa/201507-08https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2015-08-14
Published