PT-2015-3258 · Xmlsoft+5 · Libxml2+5

Hugh Davenport

·

Publicado

2015-11-18

·

Atualizado

2026-03-13

·

CVE-2015-8242

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.3
Description The issue is related to the xmlSAX2TextNode function in the HTML parser of libxml2, which allows context-dependent attackers to cause a denial of service or obtain sensitive information via crafted XML data. This can lead to a stack-based buffer over-read and application crash. The vulnerability can be exploited by a remote attacker using specially formed XML data.
Recommendations For versions prior to 2.9.3, update to version 2.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xmlSAX2TextNode function in the HTML parser until a patch is available. Avoid using the xmlSAX2TextNode function with untrusted XML data until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2016
BDU:2016-01647
CESA-2015_2549
CESA-2015_2550
CVE-2015-8242
MGASA-2015-0457
OPENSUSE-SU-2024:10192-1
OPENSUSE-SU-2024:10549-1
OPENSUSE-SU-2024:11340-1
OPENSUSE-SU-2024:11912-1
OPENSUSE-SU-2024:13165-1
OPENSUSE-SU-2024:14174-1
OPENSUSE-SU-2025:14697-1
OPENSUSE-SU-2026:10356-1
RHSA-2015:2549
RHSA-2015:2550
RHSA-2015_2549
RHSA-2015_2550
SUSE-SU-2016:0030-1
SUSE-SU-2016:0049-1
SUSE-SU-2016:0786-1
USN-2834-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2