CVE-2015-7498
published 2015-12-15CVE-2015-7498: Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.02%
93.4th percentile
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1 (bookworm) | libxml2 2.9.3+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| xmlsoft | libxml2 | <= 2.9.2 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.6 | 2.9.1+dfsg1-3ubuntu4.6 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_redhat6.8MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: May fail to delete images in resize state regression
vendor_redhat·2016-09-21·CVSS 6.8
CVE-2016-7498 [MEDIUM] CWE-400 openstack-nova: May fail to delete images in resize state regression
openstack-nova: May fail to delete images in resize state regression
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
Package: openstack-nova (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: openstack-nova (Red Hat OpenStack Platform 9 (Mitaka)) - Not affected
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled cer
Red Hat
libxml2: Heap-based buffer overflow in xmlParseXmlDecl
vendor_redhat·2015-12-01·CVSS 5.0
CVE-2015-7498 [MEDIUM] CWE-122 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
libxml2: Heap-based buffer overflow in xmlParseXmlDecl
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2015-7498: libxml2 - Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml...
vendor_debian·2015·CVSS 5.0
CVE-2015-7498 [MEDIUM] CVE-2015-7498: libxml2 - Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml...
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+dfsg1-1)
trixie: resolved (fixed in 2.9.3+dfsg1-1)
GHSA
GHSA-h3v6-m99p-pjm8: Heap-based buffer overflow in the xmlParseXmlDecl function in parser
ghsa_unreviewed·2022-05-17
CVE-2015-7498 [MEDIUM] CWE-119 GHSA-h3v6-m99p-pjm8: Heap-based buffer overflow in the xmlParseXmlDecl function in parser
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
OSV
CVE-2015-7498: Heap-based buffer overflow in the xmlParseXmlDecl function in parser
osv·2015-12-15·CVSS 5.0
CVE-2015-7498 [MEDIUM] CVE-2015-7498: Heap-based buffer overflow in the xmlParseXmlDecl function in parser
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
OSV
libxml2 vulnerabilities
osv·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a spe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7498 openstack-nova: May fail to delete images in resize state regression
bugzilla·2016-09-23·CVSS 6.8
CVE-2016-7498 [MEDIUM] CVE-2016-7498 openstack-nova: May fail to delete images in resize state regression
CVE-2016-7498 openstack-nova: May fail to delete images in resize state regression
If an authenticated user deletes an instance while it is in resize state, it
will cause the original instance to not be deleted from the compute
node it was running on. An attacker can use this to launch a denial of
service attack. All Nova setups are affected.
Affects
~~~~~~~
- Nova: ==13.0.0
Patches
~~~~~~~
- https://review.openstack.org/327398 (Mitaka)
- https://review.openstack.org/326262 (Newton)
Credits
~~~~~~~
- Rajesh Tailor from Red Hat (CVE-2016-7498)
References
~~~~~~~~~~
- https://bugs.launchpad.net/bugs/1589821
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7498
Notes
~~~~~
- This bug is similar to OSSA-2015-017 (CVE-2015-3280) and was
re-introduced in the first release of Mitak
Bugzilla
CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7498 [MEDIUM] CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
Heap-based buffer overflow was found in xmlParseXmlDecl. When conversion failure happens, parser continues to extract more errors which may lead to unexpected behaviour.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756527
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43
Discussion:
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been add
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79548http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1281879https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79548http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1281879https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37
2015-12-15
Published