CVE-2015-7500

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2015-2549.html Third Party Advisory
https://git.gnome.org/browse/libxml2/commit/?id=f1063fdbe7fa66332bbb76874101c2a7b51b519f
http://www.ubuntu.com/usn/USN-2834-1 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1281943 Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-2550.html Third Party Advisory
http://xmlsoft.org/news.html Vendor Advisory
https://support.apple.com/HT206166 Vendor Advisory
https://support.apple.com/HT206169 Vendor Advisory
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html Mailing List Third Party Advisory
https://support.apple.com/HT206168 Vendor Advisory
http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html Mailing List Third Party Advisory
https://support.apple.com/HT206167 Vendor Advisory
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html Mailing List Third Party Advisory
http://www.debian.org/security/2015/dsa-3430 Third Party Advisory
http://marc.info/?l=bugtraq&m=145382616617563&w=2 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://www.securityfocus.com/bid/79562
http://rhn.redhat.com/errata/RHSA-2016-1089.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html
http://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html
https://security.gentoo.org/glsa/201701-37
http://www.securitytracker.com/id/1034243
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:icewall_file_manager:3.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:icewall_federation_agent:3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*

History

13 Feb 2023, 00:53

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:2550', 'name': 'https://access.redhat.com/errata/RHSA-2015:2550', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:1089', 'name': 'https://access.redhat.com/errata/RHSA-2016:1089', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-7500', 'name': 'https://access.redhat.com/security/cve/CVE-2015-7500', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:2549', 'name': 'https://access.redhat.com/errata/RHSA-2015:2549', 'tags': [], 'refsource': 'MISC'}
Summary A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash. The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.

02 Feb 2023, 21:15

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2015:2550 -
  • (MISC) https://access.redhat.com/errata/RHSA-2016:1089 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-7500 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:2549 -
Summary The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.

Information

Published : 2015-12-15 21:59

Updated : 2023-02-13 00:53


NVD link : CVE-2015-7500

Mitre link : CVE-2015-7500


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_hpc_node
  • enterprise_linux_desktop
  • enterprise_linux_server

apple

  • mac_os_x
  • watchos
  • iphone_os
  • tvos

debian

  • debian_linux

hp

  • icewall_file_manager
  • icewall_federation_agent

xmlsoft

  • libxml2

canonical

  • ubuntu_linux
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer