CVE-2015-7995
published 2015-11-17CVE-2015-7995: The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.16%
89.7th percentile
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 9.2 | — |
| apple | mac_os_x | <= 10.11.2 | — |
| apple | os_x_el_capitan_10.11.3_and_security_update_2016-001 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| debian | libxslt | < libxslt 1.1.28-2.1 (bookworm) | libxslt 1.1.28-2.1 (bookworm) |
| android | — | — | |
| xmlsoft | libxslt | <= 1.1.28 | — |
| xmlsoft | libxslt | >= 0 < 1.1.28-2.1 | 1.1.28-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.28-2.1 | 1.1.28-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.28-2.1 | 1.1.28-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.28-2.1 | 1.1.28-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.28-2ubuntu0.1 | 1.1.28-2ubuntu0.1 |
| xmlsoft | libxslt | >= 0 < 1.1.28-2.1ubuntu0.1 | 1.1.28-2.1ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-7995: Android Security Bulletin 2017-06-01
CVE: CVE-2015-7995
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4
vendor_android·2017-06-01·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: Android Security Bulletin 2017-06-01
CVE: CVE-2015-7995
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4
Android Security Bulletin 2017-06-01
CVE: CVE-2015-7995
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4.4.4
References: A-36810065*
Ubuntu
Libxslt vulnerabilities
vendor_ubuntu·2017-04-28·CVSS 5.0
CVE-2015-7995 [MEDIUM] Libxslt vulnerabilities
Title: Libxslt vulnerabilities
Summary: Several security issues were fixed in Libxslt.
Holger Fuhrmannek discovered an integer overflow in the
xsltAddTextString() function in Libxslt. An attacker could use
this to craft a malicious document that, when opened, could cause a
denial of service (application crash) or possible execute arbitrary
code. (CVE-2017-5029)
Nicolas Gregoire discovered that Libxslt mishandled namespace
nodes. An attacker could use this to craft a malicious document that,
when opened, could cause a denial of service (application crash)
or possibly execute arbtrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 12.04 LTS. (CVE-2016-1683)
Sebastian Apelt discovered that a use-after-error existed in the
xsltDocumentFunctionLoadDocument() f
Red Hat
libxslt: Type confusion may cause DoS
vendor_redhat·2015-08-26·CVSS 5.0
CVE-2015-7995 [MEDIUM] CWE-587 libxslt: Type confusion may cause DoS
libxslt: Type confusion may cause DoS
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
A type confusion vulnerability was discovered in the xsltStylePreCompute() function of libxslt. A remote attacker could possibly exploit this flaw to cause an application using libxslt to crash by tricking the application into processing a specially crafted XSLT document.
Package: libxslt (Red Hat Enterprise Linux 5) - Will not fix
Package: libxslt (Red Hat Enterprise Linux 6) - Will not fix
Package: libxslt (Red Hat Enterprise Linux 7) - Will not fix
Package: libxslt (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) -
Debian
CVE-2015-7995: libxslt - The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check i...
vendor_debian·2015·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: libxslt - The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check i...
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Scope: local
bookworm: resolved (fixed in 1.1.28-2.1)
bullseye: resolved (fixed in 1.1.28-2.1)
forky: resolved (fixed in 1.1.28-2.1)
sid: resolved (fixed in 1.1.28-2.1)
trixie: resolved (fixed in 1.1.28-2.1)
Apple
CVE-2015-7995: Apple TV 7.2.1
vendor_apple·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-7995
Component: CVE-ID
Apple
CVE-2015-7995: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-7995
Component: CVE-ID
Apple
CVE-2015-7995: iOS 9.2.1
vendor_apple·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: iOS 9.2.1
Apple Security Update: About the security content of iOS 9.2.1
Product: iOS
Version: 9.2.1
CVE: CVE-2015-7995
Component: CVE-ID
Impact: A local user may be able to execute arbitrary code with root privileges
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2015-7995: tvOS 9.1.1
vendor_apple·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: tvOS 9.1.1
Apple Security Update: About the security content of tvOS 9.1.1
Product: tvOS
Version: 9.1.1
CVE: CVE-2015-7995
Component: CVE-ID
Impact: A local user may be able to execute arbitrary code with root privileges
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2015-7995: OS X El Capitan 10.11.3 and Security Update 2016-001
vendor_apple·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: OS X El Capitan 10.11.3 and Security Update 2016-001
Apple Security Update: About the security content of OS X El Capitan 10.11.3 and Security Update 2016-001
Product: OS X El Capitan 10.11.3 and Security Update 2016-001
CVE: CVE-2015-7995
Component: CVE-ID
GHSA
GHSA-57m4-4wjx-3w7c: The xsltStylePreCompute function in preproc
ghsa_unreviewed·2022-05-14
CVE-2015-7995 [MEDIUM] GHSA-57m4-4wjx-3w7c: The xsltStylePreCompute function in preproc
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
OSV
libxslt vulnerabilities
osv·2017-04-28·CVSS 5.0
CVE-2017-5029 [MEDIUM] libxslt vulnerabilities
libxslt vulnerabilities
Holger Fuhrmannek discovered an integer overflow in the
xsltAddTextString() function in Libxslt. An attacker could use
this to craft a malicious document that, when opened, could cause a
denial of service (application crash) or possible execute arbitrary
code. (CVE-2017-5029)
Nicolas Gregoire discovered that Libxslt mishandled namespace
nodes. An attacker could use this to craft a malicious document that,
when opened, could cause a denial of service (application crash)
or possibly execute arbtrary code. This issue only affected Ubuntu
16.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 12.04 LTS. (CVE-2016-1683)
Sebastian Apelt discovered that a use-after-error existed in the
xsltDocumentFunctionLoadDocument() function in Libxslt. An attacker
could use this to craft a malici
OSV
CVE-2015-7995: The xsltStylePreCompute function in preproc
osv·2015-11-17·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995: The xsltStylePreCompute function in preproc
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7995 libxslt: Type confusion may cause DoS [fedora-all]
bugzilla·2015-08-28·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995 libxslt: Type confusion may cause DoS [fedora-all]
CVE-2015-7995 libxslt: Type confusion may cause DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2015-7995 mingw-libxslt: libxslt: Type confusion may cause DoS [epel-7]
bugzilla·2015-08-28·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995 mingw-libxslt: libxslt: Type confusion may cause DoS [epel-7]
CVE-2015-7995 mingw-libxslt: libxslt: Type confusion may cause DoS [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw-libxslt: see blocks bug
Bugzilla
CVE-2015-7995 libxslt: Type confusion may cause DoS
bugzilla·2015-08-28·CVSS 5.0
CVE-2015-7995 [MEDIUM] CVE-2015-7995 libxslt: Type confusion may cause DoS
CVE-2015-7995 libxslt: Type confusion may cause DoS
A vulnerability in function xsltStylePreCompute" in preproc.c was found, the cause of which is a type confusion leading to DoS.
As reported in https://bugzilla.redhat.com/show_bug.cgi?id=1257058 :
"""
Through analysis we get to know that parent->ns->href in line 2250 of preproc.c is an invalid value with our poc.
The whole process is as follow:
1> The main function in xsltproc.c will call xmlReadFile to read a .xml file. xmlReadFile will return a xmlDocPtr which points to the xmlDoc. When we print xmlDocPtr->children->parent->ns, its value is 0xffffffff. Obviously, this value is not a correct one.
2> Later in xsltStylePreCompute of preproc.c, the function will see whether current element is 'attribute', if yes,if inst->parent!=NULL and
http://lists.apple.com/archives/security-announce/2016/Jan/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jan/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jan/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00123.htmlhttp://www.debian.org/security/2016/dsa-3605http://www.openwall.com/lists/oss-security/2015/10/27/10http://www.openwall.com/lists/oss-security/2015/10/28/4http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.securityfocus.com/bid/77325http://www.securitytracker.com/id/1034736http://www.securitytracker.com/id/1038623http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.386546https://bugzilla.redhat.com/show_bug.cgi?id=1257962https://git.gnome.org/browse/libxslt/commit/?id=7ca19df892ca22d9314e95d59ce2abdeff46b617https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://puppet.com/security/cve/cve-2015-7995https://support.apple.com/HT205729https://support.apple.com/HT205731https://support.apple.com/HT205732https://support.apple.com/HT206168http://lists.apple.com/archives/security-announce/2016/Jan/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jan/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jan/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00123.htmlhttp://www.debian.org/security/2016/dsa-3605http://www.openwall.com/lists/oss-security/2015/10/27/10http://www.openwall.com/lists/oss-security/2015/10/28/4http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.securityfocus.com/bid/77325http://www.securitytracker.com/id/1034736http://www.securitytracker.com/id/1038623http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.386546https://bugzilla.redhat.com/show_bug.cgi?id=1257962https://git.gnome.org/browse/libxslt/commit/?id=7ca19df892ca22d9314e95d59ce2abdeff46b617https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://puppet.com/security/cve/cve-2015-7995https://support.apple.com/HT205729https://support.apple.com/HT205731https://support.apple.com/HT205732https://support.apple.com/HT206168
2015-11-17
Published