CVE-2015-8317
published 2015-12-15CVE-2015-8317: The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
5.91%
92.4th percentile
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | itunes_12.4.2_for_windows | — | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.2+zdfsg1-4 (bookworm) | libxml2 2.9.2+zdfsg1-4 (bookworm) |
| hp | icewall_federation_agent | — | — |
| hp | icewall_file_manager | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| xmlsoft | libxml2 | <= 2.9.2 | — |
| xmlsoft | libxml2 | >= 0 < 2.9.2+zdfsg1-4 | 2.9.2+zdfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.2+zdfsg1-4 | 2.9.2+zdfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.2+zdfsg1-4 | 2.9.2+zdfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.2+zdfsg1-4 | 2.9.2+zdfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.6 | 2.9.1+dfsg1-3ubuntu4.6 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-8317: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2015-8317
Component: LibreSSL
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple issues existed in LibreSSL before 2.2.7. These were addressed by updating LibreSSL to version 2.2.7.
Apple
CVE-2015-8317: iTunes 12.4.2 for Windows
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: iTunes 12.4.2 for Windows
Apple Security Update: About the security content of iTunes 12.4.2 for Windows
Product: iTunes 12.4.2 for Windows
CVE: CVE-2015-8317
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2015-8317: iCloud for Windows 5.2.1
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: iCloud for Windows 5.2.1
Apple Security Update: About the security content of iCloud for Windows 5.2.1
Product: iCloud for Windows
Version: 5.2.1
CVE: CVE-2015-8317
Component: About Apple security updates
Impact: Multiple vulnerabilities in libxml2
Description: Multiple memory corruption issues were addressed through improved memory handling.
Apple
CVE-2015-8317: tvOS 9.2.2
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2015-8317
Component: Kernel
Impact: A local user may be able to cause a system denial of service
Description: A null pointer dereference was addressed through improved input validation.
Apple
CVE-2015-8317: watchOS 2.2.2
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2015-8317
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
Apple
CVE-2015-8317: iOS 9.3.3
vendor_apple·2016-07-18·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2015-8317
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 could be made to crash if it opened a specially crafted file.
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled cer
Red Hat
libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
vendor_redhat·2015-06-29·CVSS 5.0
CVE-2015-8317 [MEDIUM] CWE-125 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to leak potentially sensitive information.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Debian
CVE-2015-8317: libxml2 - The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-...
vendor_debian·2015·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: libxml2 - The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-...
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
Scope: local
bookworm: resolved (fixed in 2.9.2+zdfsg1-4)
bullseye: resolved (fixed in 2.9.2+zdfsg1-4)
forky: resolved (fixed in 2.9.2+zdfsg1-4)
sid: resolved (fixed in 2.9.2+zdfsg1-4)
trixie: resolved (fixed in 2.9.2+zdfsg1-4)
GHSA
GHSA-2q4w-wqgx-423v: The xmlParseXMLDecl function in parser
ghsa_unreviewed·2022-05-17
CVE-2015-8317 [MEDIUM] CWE-119 GHSA-2q4w-wqgx-423v: The xmlParseXMLDecl function in parser
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
OSV
CVE-2015-8317: The xmlParseXMLDecl function in parser
osv·2015-12-15·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317: The xmlParseXMLDecl function in parser
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
OSV
libxml2 vulnerabilities
osv·2015-12-14·CVSS 7.1
CVE-2015-5312 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Kostya Serebryany discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-5312,
CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500)
Hugh Davenport discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a specially crafted document, an attacker could possibly cause
libxml2 to crash, resulting in a denial of service. (CVE-2015-8241,
CVE-2015-8242)
Hanno Boeck discovered that libxml2 incorrectly handled certain
malformed documents. If a user or automated system were tricked into
opening a spe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8317 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-8317 [MEDIUM] CVE-2015-8317 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
CVE-2015-8317 libxml2: Out-of-bounds heap read when parsing file with unfinished xml declaration
An out-of-bounds heap read in xmlParseXMLDecl happens when a file containing unfinished xml declaration, e.g. <?xml versionencoding="ISO88598", is followed by 0xff byte.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=751631
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=709a952110e98621c9b78c4f26462a9d8333102e
Out-of-bounds heap read also occurs in xmlParseXMLDecl when file contains unterminated encoding value.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=751603
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=9aa37588ee78a06ca1379a9d9356eab16686099c
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [
Tenable
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-02-01
[R2] Nessus 6.10 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.openwall.com/lists/oss-security/2015/11/21/1http://www.openwall.com/lists/oss-security/2015/11/22/3http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77681http://www.securityfocus.com/bid/91826http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1https://blog.fuzzing-project.org/28-Libxml2-Several-out-of-bounds-reads.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=751603https://bugzilla.gnome.org/show_bug.cgi?id=751631https://bugzilla.redhat.com/show_bug.cgi?id=1281930https://git.gnome.org/browse/libxml2/commit/?id=709a952110e98621c9b78c4f26462a9d8333102ehttps://git.gnome.org/browse/libxml2/commit/?id=9aa37588ee78a06ca1379a9d9356eab16686099chttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://support.apple.com/HT206899https://support.apple.com/HT206901https://support.apple.com/HT206902https://support.apple.com/HT206903https://support.apple.com/HT206904https://support.apple.com/HT206905http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/Jul/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00031.htmlhttp://marc.info/?l=bugtraq&m=145382616617563&w=2http://rhn.redhat.com/errata/RHSA-2015-2549.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1089.htmlhttp://www.debian.org/security/2015/dsa-3430http://www.openwall.com/lists/oss-security/2015/11/21/1http://www.openwall.com/lists/oss-security/2015/11/22/3http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77681http://www.securityfocus.com/bid/91826http://www.securitytracker.com/id/1034243http://www.ubuntu.com/usn/USN-2834-1https://blog.fuzzing-project.org/28-Libxml2-Several-out-of-bounds-reads.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=751603https://bugzilla.gnome.org/show_bug.cgi?id=751631https://bugzilla.redhat.com/show_bug.cgi?id=1281930https://git.gnome.org/browse/libxml2/commit/?id=709a952110e98621c9b78c4f26462a9d8333102ehttps://git.gnome.org/browse/libxml2/commit/?id=9aa37588ee78a06ca1379a9d9356eab16686099chttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172https://support.apple.com/HT206899https://support.apple.com/HT206901https://support.apple.com/HT206902https://support.apple.com/HT206903https://support.apple.com/HT206904https://support.apple.com/HT206905
2015-12-15
Published