CVE-2015-2716
published 2015-05-14CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.42%
93.8th percentile
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| debian | expat | < expat 2.1.0-7 (bookworm) | expat 2.1.0-7 (bookworm) |
| debian | libxmltok | < expat 2.1.1-2 (bookworm) | expat 2.1.1-2 (bookworm) |
| debian | libxmltok | < expat 2.1.0-7 (bookworm) | expat 2.1.0-7 (bookworm) |
| chrome | <= 43.0.2357.134 | — | |
| libexpat_project | libexpat | <= 2.1.0 | — |
| libexpat_project | libexpat | <= 2.1.1 | — |
| mcafee | policy_auditor | < 6.5.1 | 6.5.1 |
| mozilla | firefox | <= 37.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 38.0+build3-0ubuntu0.14.04.1 | 38.0+build3-0ubuntu0.14.04.1 |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3pwf-x7h5-r7pj: Buffer overflow in the XML parser in Mozilla Firefox before 38
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2015-2716 [MEDIUM] CWE-119 GHSA-3pwf-x7h5-r7pj: Buffer overflow in the XML parser in Mozilla Firefox before 38
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
GHSA
GHSA-6w45-gwrj-v625: Multiple integer overflows in the XML_GetBuffer function in Expat through 2
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2015-1283 [HIGH] CWE-190 GHSA-6w45-gwrj-v625: Multiple integer overflows in the XML_GetBuffer function in Expat through 2
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
GHSA
GHSA-855w-qg6f-ffh7: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2016-4472 [MEDIUM] CWE-119 GHSA-855w-qg6f-ffh7: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
OSV
CVE-2016-4472: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic
osv·2016-06-30·CVSS 6.8
CVE-2016-4472 [MEDIUM] CVE-2016-4472: The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servic
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
OSV
CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2
osv·2015-07-23·CVSS 6.8
CVE-2015-1283 [MEDIUM] CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
OSV
thunderbird vulnerabilities
osv·2015-05-18·CVSS 7.5
CVE-2015-2708 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Jesse Ruderman, Mats Palmgren, Byron Campen, and Steve Fink discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted message with scripting enabled, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-2708)
Atte Kettunen discovered a buffer overflow during the rendering of SVG
content with certain CSS properties in some circumstances. If a user were
tricked in to opening a specially crafted message with scripting enabled,
an attacker could potentially exploit this to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user
OSV
firefox vulnerabilities
osv·2015-05-13·CVSS 7.5
CVE-2015-2708 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Jesse Ruderman, Mats Palmgren, Byron Campen, Steve Fink, Gary Kwong,
Andrew McCreight, Christian Holler, Jon Coppeard, and Milan Sreckovic
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-2708, CVE-2015-2709)
Atte Kettunen discovered a buffer overflow during the rendering of SVG
content with certain CSS properties in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary c
OSV
CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38
osv·2015-05-13·CVSS 6.8
CVE-2015-2716 [MEDIUM] CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Red Hat
expat: Undefined behavior and pointer overflows
vendor_redhat·2016-05-15·CVSS 6.8
CVE-2016-4472 [MEDIUM] CWE-190 expat: Undefined behavior and pointer overflows
expat: Undefined behavior and pointer overflows
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Package: expat (Red Hat Directory Server 8) - Under investigation
Package: apr-util (Red Hat Enterprise Linux 5) - Not affected
Package: dasher (Red Hat Enterprise Linux 5) - Not affected
Package: expat (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 5) - Not affect
Debian
CVE-2016-4472: expat - The overflow protection in Expat is removed by compilers with certain optimizati...
vendor_debian·2016·CVSS 6.8
CVE-2016-4472 [MEDIUM] CVE-2016-4472: expat - The overflow protection in Expat is removed by compilers with certain optimizati...
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Scope: local
bookworm: resolved (fixed in 2.1.1-2)
bullseye: resolved (fixed in 2.1.1-2)
forky: resolved (fixed in 2.1.1-2)
sid: resolved (fixed in 2.1.1-2)
trixie: resolved (fixed in 2.1.1-2)
Red Hat
chromium-browser: Heap-buffer-overflow in expat.
vendor_redhat·2015-07-21·CVSS 6.8
CVE-2015-1283 [MEDIUM] CWE-122 chromium-browser: Heap-buffer-overflow in expat.
chromium-browser: Heap-buffer-overflow in expat.
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-05-18·CVSS 7.5
CVE-2015-2708 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Jesse Ruderman, Mats Palmgren, Byron Campen, and Steve Fink discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted message with scripting enabled, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-2708)
Atte Kettunen discovered a buffer overflow during the rendering of SVG
content with certain CSS properties in some circumstances. If a user were
tricked in to opening a specially crafted message with scripting enabled,
an attacker could potentially exploit this to cause a denial of service
via applicati
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-05-13·CVSS 7.5
CVE-2015-2708 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Jesse Ruderman, Mats Palmgren, Byron Campen, Steve Fink, Gary Kwong,
Andrew McCreight, Christian Holler, Jon Coppeard, and Milan Sreckovic
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-2708, CVE-2015-2709)
Atte Kettunen discovered a buffer overflow during the rendering of SVG
content with certain CSS properties in some circumstances. If a user were
tricked in to opening a specially crafted website, an at
Red Hat
expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
vendor_redhat·2015-05-12·CVSS 6.8
CVE-2015-2716 [MEDIUM] expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Statement: This issue affects the version of expat package as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact, a future update may address this flaw.
Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates.
Package: expat (Red Hat Enterprise Linux 5) - Will not fi
Debian
CVE-2015-1283: expat - Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0,...
vendor_debian·2015·CVSS 6.8
CVE-2015-1283 [MEDIUM] CVE-2015-1283: expat - Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0,...
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
Scope: local
bookworm: resolved (fixed in 2.1.0-7)
bullseye: resolved (fixed in 2.1.0-7)
forky: resolved (fixed in 2.1.0-7)
sid: resolved (fixed in 2.1.0-7)
trixie: resolved (fixed in 2.1.0-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows
bugzilla·2016-06-09·CVSS 6.8
CVE-2016-4472 [MEDIUM] CVE-2016-4472 expat: Undefined behavior and pointer overflows
CVE-2016-4472 expat: Undefined behavior and pointer overflows
It was found that original patch for issues CVE-2015-1283 and CVE-2015-2716 used overflow checks that could be optimized out by some compilers applying certain optimization settings, which can cause the vulnerability to remain even after applying the patch.
One pattern in the fix for CVE-2015-1283/CVE-2015-2716 is:
/* bufferSize is positive here */
do {
bufferSize *= 2;
} while (bufferSize 0);
if (bufferSize 0 as always true when the execution is defined, and bufferSize 0 out of the loop, that is, compile the code as if it had been written:
if (bufferSize <= 0)
errorCode = XML_ERROR_NO_MEMORY;
return NULL;
else {
do {
bufferSize *= 2;
} while (bufferSize < neededSize);
}
Both cases leads to not eliminating the vulnerability
Bugzilla
CVE-2015-1283 chromium-browser: Heap-buffer-overflow in expat.
bugzilla·2015-07-22·CVSS 6.8
CVE-2015-1283 [MEDIUM] CVE-2015-1283 chromium-browser: Heap-buffer-overflow in expat.
CVE-2015-1283 chromium-browser: Heap-buffer-overflow in expat.
An unspecified heap-buffer-overflow flaw was found in the expat component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=492052
External References:
http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1499 https://rhn.redhat.com/errata/RHSA-2015-1499.html
---
This is the same flaw was CVE-2015-2716 as documented in the Mozilla advisory at:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-54/
However in chromium, libxml2 is used to parse XML web content, expat is used a dependency of libjingle and other associate
Bugzilla
CVE-2015-2716 expat: Mozilla: Buffer overflow when parsing compressed XML (MFSA 2015-54) [fedora-all]
bugzilla·2015-06-17·CVSS 7.5
CVE-2015-2716 [HIGH] CVE-2015-2716 expat: Mozilla: Buffer overflow when parsing compressed XML (MFSA 2015-54) [fedora-all]
CVE-2015-2716 expat: Mozilla: Buffer overflow when parsing compressed XML (MFSA 2015-54) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2015-2716 expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
bugzilla·2015-05-12·CVSS 7.5
CVE-2015-2716 [HIGH] CVE-2015-2716 expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
CVE-2015-2716 expat: Integer overflow leading to buffer overflow in XML_GetBuffer()
Security researcher Ucha Gobejishvili used the Address Sanitizer tool to find a buffer overflow while parsing compressed XML content. This was due to an error in how buffer space is created and modified when handling large amounts of XML data. This results in a potentially exploitable crash.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2015/mfsa2015-54.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Ucha Gobejishvili as the original reporter
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00036.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0988.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1012.htmlhttp://www.debian.org/security/2015/dsa-3260http://www.debian.org/security/2015/dsa-3264http://www.mozilla.org/security/announce/2015/mfsa2015-54.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74611http://www.ubuntu.com/usn/USN-2602-1http://www.ubuntu.com/usn/USN-2603-1https://bugzilla.mozilla.org/show_bug.cgi?id=1140537https://hg.mozilla.org/releases/mozilla-esr31/rev/2f3e78643f5chttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://security.gentoo.org/glsa/201605-06https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7https://www.tenable.com/security/tns-2016-20http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00036.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0988.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1012.htmlhttp://www.debian.org/security/2015/dsa-3260http://www.debian.org/security/2015/dsa-3264http://www.mozilla.org/security/announce/2015/mfsa2015-54.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/74611http://www.ubuntu.com/usn/USN-2602-1http://www.ubuntu.com/usn/USN-2603-1https://bugzilla.mozilla.org/show_bug.cgi?id=1140537https://hg.mozilla.org/releases/mozilla-esr31/rev/2f3e78643f5chttps://kc.mcafee.com/corporate/index?page=content&id=SB10365https://security.gentoo.org/glsa/201605-06https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7https://www.tenable.com/security/tns-2016-20
2015-05-14
Published