Severity
4.3MEDIUM
EPSS
0.5%
top 32.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 17

Description

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianlibxml2< 2.9.2+really2.9.1+dfsg1-0.1+3
NVDxmlsoft/libxml22.9.2

Also affects: Ubuntu Linux 12.04, 14.04, 15.04

🔴Vulnerability Details

4
GHSA
GHSA-v48g-p9p2-j8cr: libxml2 22022-05-17
CVEList
CVE-2015-7941: libxml2 22015-11-18
OSV
CVE-2015-7941: libxml2 22015-11-18
OSV
libxml2 vulnerabilities2015-11-16

📋Vendor Advisories

4
Ubuntu
libxml2 vulnerabilities2015-11-16
Red Hat
libxml2: heap-based buffer overflow in xmlParseConditionalSections()2015-10-22
Red Hat
libxml2: Out-of-bounds memory access2015-02-22
Debian
CVE-2015-7941: libxml2 - libxml2 2.9.2 does not properly stop parsing invalid input, which allows context...2015

💬Community

6
Bugzilla
libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O2015-11-13
Bugzilla
CVE-2015-7941 libxml2: Out-of-bounds memory access [fedora-all]2015-10-22
Bugzilla
CVE-2015-7941 mingw-libxml2: libxml2: Out-of-bounds memory access [fedora-all]2015-10-22
Bugzilla
CVE-2015-7941 mingw-libxml2: libxml2: Out-of-bounds memory access [epel-7]2015-10-22
Bugzilla
CVE-2015-7941 libxml2: Out-of-bounds memory access2015-10-22
CVE-2015-7941 (MEDIUM CVSS 4.3) | libxml2 2.9.2 does not properly sto | cvebase.io