PT-2015-3254 · Xmlsoft+5 · Libxml2+5

Adam Mariš

·

Published

2015-11-20

·

Updated

2026-03-13

·

CVE-2015-7498

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.3
Description The issue is related to a heap-based buffer overflow in the xmlParseXmlDecl function, which can be exploited by context-dependent attackers to cause a denial of service. This occurs via unspecified vectors related to extracting errors after an encoding conversion failure. The vulnerability allows a remote attacker to cause a denial of service by influencing the extraction of errors after a coding process failure.
Recommendations For libxml2 versions prior to 2.9.3, update to version 2.9.3 or later to resolve the issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2016
BDU:2016-01643
CESA-2015_2549
CESA-2015_2550
CVE-2015-7498
DLA-373-1
DSA-3430-1
MGASA-2015-0457
OPENSUSE-SU-2024:10192-1
OPENSUSE-SU-2024:10549-1
OPENSUSE-SU-2024:11340-1
OPENSUSE-SU-2024:11912-1
OPENSUSE-SU-2024:13165-1
OPENSUSE-SU-2024:14174-1
OPENSUSE-SU-2025:14697-1
OPENSUSE-SU-2026:10356-1
RHSA-2015:2549
RHSA-2015:2550
RHSA-2015_2549
RHSA-2015_2550
SUSE-SU-2016:0030-1
SUSE-SU-2016:0049-1
SUSE-SU-2016:0786-1
USN-2834-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2