Severity
2.6LOW
EPSS
1.1%
top 21.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 14

Description

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

CVSS vector

AV:N/AC:H/C:N/I:N/A:PExploitability: 4.9 | Impact: 2.9

Affected Packages6 packages

Debianlibxml2< 2.9.3+dfsg1-1+3
NVDxmlsoft/libxml22.9.1
NVDapple/tvos9.1
NVDapple/watchos2.1
NVDapple/mac_os_x10.11.3

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 14.04

🔴Vulnerability Details

3
GHSA
GHSA-cprg-r8c2-9m62: The xz_decomp function in xzlib2022-05-14
OSV
CVE-2015-8035: The xz_decomp function in xzlib2015-11-18
CVEList
CVE-2015-8035: The xz_decomp function in xzlib2015-11-18

📋Vendor Advisories

9
Red Hat
libxml2: Infinite loop caused by incorrect error detection during LZMA decompression2018-04-03
Red Hat
libxml2: infinite loop in xz_decomp function in xzlib.c2018-04-03
Ubuntu
libxml2 vulnerabilities2015-11-16
Red Hat
libxml2: DoS caused by incorrect error detection during XZ decompression2015-11-02
Debian
CVE-2015-8035: libxml2 - The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect comp...2015

💬Community

6
Bugzilla
CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression2018-08-22
Bugzilla
CVE-2018-9251 libxml2: infinite loop in xz_decomp function in xzlib.c2018-04-09
Bugzilla
CVE-2015-8035 mingw-libxml2: libxml2: DoS when parsing specially crafted XML document if XZ support is enabled [epel-7]2015-11-02
Bugzilla
CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ decompression2015-11-02
Bugzilla
CVE-2015-8035 libxml2: DoS when parsing specially crafted XML document if XZ support is enabled [fedora-all]2015-11-02
CVE-2015-8035 (LOW CVSS 2.6) | The xz_decomp function in xzlib.c i | cvebase.io