CVE-2015-5312
published 2015-12-15CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent…
PriorityP434high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
4.54%
90.5th percentile
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1 (bookworm) | libxml2 2.9.3+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.7.1 | 1.6.7.1 |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| xmlsoft | libxml2 | <= 2.9.2 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
ghsa5.0MEDIUM
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled cer
Red Hat
libxml2: CPU exhaustion when processing specially crafted XML input
vendor_redhat·2015-12-01·CVSS 5.0
CVE-2015-5312 [MEDIUM] libxml2: CPU exhaustion when processing specially crafted XML input
libxml2: CPU exhaustion when processing specially crafted XML input
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to use an excessive amount of CPU.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2015-5312: libxml2 - The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does...
vendor_debian·2015·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: libxml2 - The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does...
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+dfsg1-1)
trixie: resolved (fixed in 2.9.3+dfsg1-1)
Apple
CVE-2015-5312: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-5312: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-5312: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-5312
Component: CVE-2015-1819
Apple
CVE-2015-5312: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-5312
Component: CVE-2015-1819
OSV
Nokogiri subject to DoS via libxml2 vulnerability
osv·2018-08-21·CVSS 5.0
CVE-2015-5312 [MEDIUM] Nokogiri subject to DoS via libxml2 vulnerability
Nokogiri subject to DoS via libxml2 vulnerability
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 (as used in nokogiri before 1.6.7.1) does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
GHSA
Nokogiri subject to DoS via libxml2 vulnerability
ghsa·2018-08-21·CVSS 5.0
CVE-2015-5312 [MEDIUM] CWE-400 Nokogiri subject to DoS via libxml2 vulnerability
Nokogiri subject to DoS via libxml2 vulnerability
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 (as used in nokogiri before 1.6.7.1) does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
OSV
CVE-2015-5312: The xmlStringLenDecodeEntities function in parser
osv·2015-12-15·CVSS 5.0
CVE-2015-5312 [MEDIUM] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
OSV
libxml2 vulnerabilities
osv·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a spe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
bugzilla·2015-10-30·CVSS 7.1
CVE-2015-5312 [HIGH] CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
A vulnerability in libxml2 was found causing DoS by exhausting CPU when parsing specially crafted XML document.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756733
Discussion:
Created attachment 1087984
Proposed patch
Patch proposed by Google Security Team.
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=69030714cde66d525a8884bda01b9e8f0abf8e1e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2550 https://rhn.redhat.com/errata/RHSA-2015-2550.html
---
T
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79536http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1276693https://git.gnome.org/browse/libxml2/commit/?id=69030714cde66d525a8884bda01b9e8f0abf8e1ehttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79536http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1276693https://git.gnome.org/browse/libxml2/commit/?id=69030714cde66d525a8884bda01b9e8f0abf8e1ehttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2015-12-15
Published