CVE-2015-8242
published 2015-12-15CVE-2015-8242: The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
4.27%
90.0th percentile
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libxml2 | < libxml2 2.9.3+dfsg1-1 (bookworm) | libxml2 2.9.3+dfsg1-1 (bookworm) |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| xmlsoft | libxml2 | <= 2.9.2 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1 | 2.9.3+dfsg1-1 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.6 | 2.9.1+dfsg1-3ubuntu4.6 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f254-qfhg-6649: The xmlSAX2TextNode function in SAX2
ghsa_unreviewed·2022-05-14
CVE-2015-8242 [MEDIUM] CWE-119 GHSA-f254-qfhg-6649: The xmlSAX2TextNode function in SAX2
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
OSV
CVE-2015-8242: The xmlSAX2TextNode function in SAX2
osv·2015-12-15·CVSS 5.8
CVE-2015-8242 [MEDIUM] CVE-2015-8242: The xmlSAX2TextNode function in SAX2
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
OSV
libxml2 vulnerabilities
osv·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a spe
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled cer
Red Hat
libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
vendor_redhat·2015-10-11·CVSS 5.8
CVE-2015-8242 [MEDIUM] libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to leak potentially sensitive information.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2015-8242: libxml2 - The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser ...
vendor_debian·2015·CVSS 5.8
CVE-2015-8242 [MEDIUM] CVE-2015-8242: libxml2 - The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser ...
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+dfsg1-1)
trixie: resolved (fixed in 2.9.3+dfsg1-1)
Apple
CVE-2015-8242: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-8242: tvOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-8242: watchOS 2.2
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2015-8242
Component: CVE-2015-7499
Apple
CVE-2015-8242: iOS 9.3
vendor_apple·CVSS 5.0
CVE-2015-8242 [MEDIUM] CVE-2015-8242: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-8242
Component: CVE-2015-7499
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8242 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
bugzilla·2015-11-13·CVSS 5.8
CVE-2015-8242 [MEDIUM] CVE-2015-8242 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
CVE-2015-8242 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode
Stack-based buffer overread vulnerability with HTML parser in push mode in xmlSAX2TextNode causing segmentation fault when compiled with ASAN.
Upstream bug (containing reproducer):
https://bugzilla.gnome.org/show_bug.cgi?id=756372
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1281951]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1281952]
Affects: epel-7 [bug 1281953]
---
Acknowledgments:
Name: the GNOME project
Upstream: Hugh Davenport
---
CVE assignment:
http://openwall.com/lists/oss-security/2015/11/18/23
---
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=8fb4a770075628d6441fb17a1e435100e2f3b1a2
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.openwall.com/lists/oss-security/2015/11/17/5http://www.openwall.com/lists/oss-security/2015/11/18/23http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77681http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=756372https://bugzilla.redhat.com/show_bug.cgi?id=1281950https://git.gnome.org/browse/libxml2/commit/?id=8fb4a770075628d6441fb17a1e435100e2f3b1a2https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2550.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.openwall.com/lists/oss-security/2015/11/17/5http://www.openwall.com/lists/oss-security/2015/11/18/23http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77681http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1http://xmlsoft.org/news.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=756372https://bugzilla.redhat.com/show_bug.cgi?id=1281950https://git.gnome.org/browse/libxml2/commit/?id=8fb4a770075628d6441fb17a1e435100e2f3b1a2https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://security.gentoo.org/glsa/201701-37https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2015-12-15
Published