CVE-2015-8317

Severity
5.0MEDIUM
EPSS
0.3%
top 47.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 17

Description

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages8 packages

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

🔴Vulnerability Details

3
GHSA
GHSA-2q4w-wqgx-423v: The xmlParseXMLDecl function in parser2022-05-17
CVEList
CVE-2015-8317: The xmlParseXMLDecl function in parser2015-12-15
OSV
CVE-2015-8317: The xmlParseXMLDecl function in parser2015-12-15

📋Vendor Advisories

9
Apple
CVE-2015-8317: OS X El Capitan v10.11.6 and Security Update 2016-0042016-07-18
Apple
CVE-2015-8317: iTunes 12.4.2 for Windows2016-07-18
Apple
CVE-2015-8317: iCloud for Windows 5.2.12016-07-18
Apple
CVE-2015-8317: tvOS 9.2.22016-07-18
Apple
CVE-2015-8317: watchOS 2.2.22016-07-18

💬Community

1
Bugzilla
CVE-2015-8317 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration2015-11-13
CVE-2015-8317 (MEDIUM CVSS 5) | The xmlParseXMLDecl function in par | cvebase.io