Resource management error in Libxml2 - CVE-2015-1819

 

Resource management error in Libxml2 - CVE-2015-1819

Published: August 14, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32385
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1819
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.


Affected software

Libxml2
Amazon Linux AMI
Gentoo Linux
Fedora
libxml2 (Alpine package)
libxml2

How to mitigate CVE-2015-1819

Install update from vendor's website.

libxml2 (Alpine package) - addressed in versions 2.9.1-r3, 2.9.1-r4
libxml2 - addressed in versions 2.9.3-1.fc22, 2.9.3-1.fc23

External References

Related Security Bulletins