CVE-2015-8242

CWE-119Buffer Overflow13 documents9 sources
Severity
5.8MEDIUM
EPSS
1.4%
top 19.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 14

Description

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVSS vector

AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages12 packages

Debianlibxml2< 2.9.3+dfsg1-1+3
NVDxmlsoft/libxml22.9.2
NVDapple/tvos9.1
NVDapple/watchos2.1
NVDapple/mac_os_x10.11.3

Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-f254-qfhg-6649: The xmlSAX2TextNode function in SAX22022-05-14
CVEList
CVE-2015-8242: The xmlSAX2TextNode function in SAX22015-12-15
OSV
CVE-2015-8242: The xmlSAX2TextNode function in SAX22015-12-15
OSV
libxml2 vulnerabilities2015-12-14

📋Vendor Advisories

7
Ubuntu
libxml2 vulnerabilities2015-12-14
Red Hat
libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode2015-10-11
Debian
CVE-2015-8242: libxml2 - The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser ...2015
Apple
CVE-2015-8242: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple
CVE-2015-8242: tvOS 9.2

💬Community

1
Bugzilla
CVE-2015-8242 libxml2: Buffer overread with HTML parser in push mode in xmlSAX2TextNode2015-11-13
CVE-2015-8242 (MEDIUM CVSS 5.8) | The xmlSAX2TextNode function in SAX | cvebase.io