Resource management error in Libxml2 - CVE-2015-8035
Published: November 18, 2015 / Updated: July 28, 2020
Vulnerability identifier: #VU32381
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8035
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
Affected software
Libxml2
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
libxml2 (Alpine package)
libxml2 (Red Hat package)
mingw-libxml2
libxml2
Data Computing Appliance (DCA)
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
libxml2 (Alpine package)
libxml2 (Red Hat package)
mingw-libxml2
libxml2
Data Computing Appliance (DCA)
How to mitigate CVE-2015-8035
Install update from vendor's website.
libxml2 (Alpine package) - addressed in versions 2.9.1-r3, 2.9.1-r4
libxml2 (Red Hat package) - update to 2.9.1-6.el7.4
mingw-libxml2 - addressed in versions 2.9.3-1.el7, 2.9.3-1.fc22, 2.9.3-1.fc23
libxml2 - addressed in versions 2.9.3-1.fc22, 2.9.3-1.fc23
Data Computing Appliance (DCA) - update to 4.3.0.0
libxml2 (Red Hat package) - update to 2.9.1-6.el7.4
mingw-libxml2 - addressed in versions 2.9.3-1.el7, 2.9.3-1.fc22, 2.9.3-1.fc23
libxml2 - addressed in versions 2.9.3-1.fc22, 2.9.3-1.fc23
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177341.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177381.html
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html
- http://rhn.redhat.com/errata/RHSA-2016-1089.html
- http://www.debian.org/security/2015/dsa-3430
- http://www.openwall.com/lists/oss-security/2015/11/02/2
- http://www.openwall.com/lists/oss-security/2015/11/02/4
- http://www.openwall.com/lists/oss-security/2015/11/03/1
- http://www.securityfocus.com/bid/77390
- http://www.securitytracker.com/id/1034243
- http://www.ubuntu.com/usn/USN-2812-1
- http://xmlsoft.org/news.html
- https://bugzilla.gnome.org/show_bug.cgi?id=757466
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
- https://security.gentoo.org/glsa/201701-37
- https://support.apple.com/HT206166
- https://support.apple.com/HT206167
- https://support.apple.com/HT206168
- https://support.apple.com/HT206169
Related Security Bulletins
- Resource management error in Libxml2
- Amazon Linux AMI update for libxml2
- Resource management error in libxml2 (Alpine package)
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 7 update for libxml2
- Fedora 22 update for libxml2
- Fedora 23 update for libxml2
- Fedora 23 update for mingw-libxml2
- Fedora 22 update for mingw-libxml2
- Fedora EPEL 7 update for mingw-libxml2