CVE-2015-7499
published 2015-12-15CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
6.46%
93.0th percentile
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1 (bookworm) | libxml2 2.9.3+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.7.2 | 1.6.7.2 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2016-01-19
CVE-2015-7499 libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
It was discovered that libxml2 incorrectly handled certain malformed
documents. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled cer
Red Hat
libxml2: Heap-based buffer overflow in xmlGROW
vendor_redhat·2015-12-01·CVSS 5.0
CVE-2015-7499 [MEDIUM] CWE-122 libxml2: Heap-based buffer overflow in xmlGROW
libxml2: Heap-based buffer overflow in xmlGROW
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to leak potentially sensitive information.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2015-7499: libxml2 - Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before...
vendor_debian·2015·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: libxml2 - Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before...
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+dfsg1-1)
trixie: resolved (fixed in 2.9.3+dfsg1-1)
Apple
CVE-2016-1761: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2016-1761 [MEDIUM] CVE-2016-1761: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-1761
Component: CVE-2015-7499
Apple
CVE-2015-8035: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-8035 [MEDIUM] CVE-2015-8035: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-8035
Component: CVE-2015-7499
Apple
CVE-2015-7500: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-7500 [MEDIUM] CVE-2015-7500: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-7500
Component: CVE-2015-7499
Apple
CVE-2015-7500: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-7500 [MEDIUM] CVE-2015-7500: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-7500
Component: CVE-2015-7499
Apple
CVE-2015-7499: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-7499
Component: CVE-2015-7499
Apple
CVE-2015-8242: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-7500: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-7500 [MEDIUM] CVE-2015-7500: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-7500
Component: CVE-2015-7499
Apple
CVE-2015-7500: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-7500 [MEDIUM] CVE-2015-7500: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-7500
Component: CVE-2015-7499
Apple
CVE-2015-8242: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-7942: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-7942 [MEDIUM] CVE-2015-7942: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-7942
Component: CVE-2015-7499
Apple
CVE-2015-7499: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-7499
Component: CVE-2015-7499
Apple
CVE-2015-8035: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-8035 [MEDIUM] CVE-2015-8035: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-8035
Component: CVE-2015-7499
Apple
CVE-2015-7499: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-7499
Component: CVE-2015-7499
Apple
CVE-2015-8242: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-7942: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-7942 [MEDIUM] CVE-2015-7942: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-7942
Component: CVE-2015-7499
Apple
CVE-2015-8035: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-8035 [MEDIUM] CVE-2015-8035: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-8035
Component: CVE-2015-7499
Apple
CVE-2015-7499: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-7499
Component: CVE-2015-7499
Apple
CVE-2015-8035: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-8035 [MEDIUM] CVE-2015-8035: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-8035
Component: CVE-2015-7499
Apple
CVE-2015-8242: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-7942: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-7942 [MEDIUM] CVE-2015-7942: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-7942
Component: CVE-2015-7499
Apple
CVE-2016-1761: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2016-1761 [MEDIUM] CVE-2016-1761: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2016-1761
Component: CVE-2015-7499
Apple
CVE-2016-1761: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2016-1761 [MEDIUM] CVE-2016-1761: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1761
Component: CVE-2015-7499
Apple
CVE-2015-7942: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-7942 [MEDIUM] CVE-2015-7942: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-7942
Component: CVE-2015-7499
GHSA
Heap-based buffer overflow in nokogiri
ghsa·2018-09-17
CVE-2015-7499 [MEDIUM] CWE-119 Heap-based buffer overflow in nokogiri
Heap-based buffer overflow in nokogiri
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to use an excessive amount of CPU, leak potentially sensitive information, or crash the application.
OSV
Heap-based buffer overflow in nokogiri
osv·2018-09-17
CVE-2015-7499 [MEDIUM] Heap-based buffer overflow in nokogiri
Heap-based buffer overflow in nokogiri
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to use an excessive amount of CPU, leak potentially sensitive information, or crash the application.
OSV
CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser
osv·2015-12-15·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
OSV
libxml2 vulnerabilities
osv·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a spe
No detection rules found.
No public exploits indexed.
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
A heap-based buffer overflow was found in xmlGROW allowing the attacker to read the memory out of bounds.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756479
Discussion:
Created attachment 1093836
Upstream patch
---
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commits:
https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfc
https://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0da
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Ha
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79509http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1281925https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfchttps://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0dahttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/79509http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1281925https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfchttps://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0dahttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2015-12-15
Published