PT-2015-2754 · Xmlsoft+4 · Libxml2+4
Gustavo.Grieco
·
Published
2015-11-02
·
Updated
2026-03-13
·
CVE-2015-8035
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libxml2 version 2.9.1
Description
The issue is related to the xz decomp function in xzlib.c, which does not properly handle compression errors. This allows attackers to cause a denial of service, resulting in a process hang, by providing crafted XML data. The vulnerability is also associated with resource management errors, and its exploitation can lead to a denial of service when specially formed XML data is used.
Recommendations
For libxml2 version 2.9.1, consider updating to a newer version that addresses the issue with the xz decomp function. As a temporary workaround, restrict the use of crafted XML data to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Ubuntu
Libxml2