CVE
- Id
- 85218
- CVE No.
- CVE-2015-7941
- Status
- Candidate
- Description
- libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.
- Phase
- Assigned (20151022)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
751861 | 85218 | CVE-2015-7941 | MLIST:[oss-security] 20151022 Crafted xml causes out of bound memory access - Libxml2 | View |
751862 | 85218 | CVE-2015-7941 | URL:http://www.openwall.com/lists/oss-security/2015/10/22/5 | View |
751863 | 85218 | CVE-2015-7941 | MLIST:[oss-security] 20151022 Re: Crafted xml causes out of bound memory access - Libxml2 | View |
751864 | 85218 | CVE-2015-7941 | URL:http://www.openwall.com/lists/oss-security/2015/10/22/8 | View |
751865 | 85218 | CVE-2015-7941 | CONFIRM:https://bugzilla.gnome.org/show_bug.cgi?id=744980 | View |
751866 | 85218 | CVE-2015-7941 | CONFIRM:https://git.gnome.org/browse/libxml2/commit/?id=9b8512337d14c8ddf662fcb98b0135f225a1c489 | View |
751867 | 85218 | CVE-2015-7941 | CONFIRM:https://git.gnome.org/browse/libxml2/commit/?id=a7dfab7411cbf545f359dd3157e5df1eb0e7ce31 | View |
751868 | 85218 | CVE-2015-7941 | CONFIRM:http://xmlsoft.org/news.html | View |
751869 | 85218 | CVE-2015-7941 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172 | View |
751870 | 85218 | CVE-2015-7941 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | View |
751871 | 85218 | CVE-2015-7941 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html | View |
751872 | 85218 | CVE-2015-7941 | DEBIAN:DSA-3430 | View |
751873 | 85218 | CVE-2015-7941 | URL:http://www.debian.org/security/2015/dsa-3430 | View |
751874 | 85218 | CVE-2015-7941 | FEDORA:FEDORA-2016-189a7bf68c | View |
751875 | 85218 | CVE-2015-7941 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177341.html | View |
751876 | 85218 | CVE-2015-7941 | FEDORA:FEDORA-2016-a9ee80b01d | View |
751877 | 85218 | CVE-2015-7941 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177381.html | View |
751878 | 85218 | CVE-2015-7941 | HP:HPSBGN03537 | View |
751879 | 85218 | CVE-2015-7941 | URL:http://marc.info/?l=bugtraq&m=145382616617563&w=2 | View |
751880 | 85218 | CVE-2015-7941 | REDHAT:RHSA-2015:2549 | View |
751881 | 85218 | CVE-2015-7941 | URL:http://rhn.redhat.com/errata/RHSA-2015-2549.html | View |
751882 | 85218 | CVE-2015-7941 | REDHAT:RHSA-2015:2550 | View |
751883 | 85218 | CVE-2015-7941 | URL:http://rhn.redhat.com/errata/RHSA-2015-2550.html | View |
751884 | 85218 | CVE-2015-7941 | REDHAT:RHSA-2016:1089 | View |
751885 | 85218 | CVE-2015-7941 | URL:http://rhn.redhat.com/errata/RHSA-2016-1089.html | View |
751886 | 85218 | CVE-2015-7941 | SUSE:openSUSE-SU-2015:2372 | View |
751887 | 85218 | CVE-2015-7941 | URL:http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html | View |
751888 | 85218 | CVE-2015-7941 | SUSE:openSUSE-SU-2016:0106 | View |
751889 | 85218 | CVE-2015-7941 | URL:http://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html | View |
751890 | 85218 | CVE-2015-7941 | UBUNTU:USN-2812-1 | View |
751891 | 85218 | CVE-2015-7941 | URL:http://www.ubuntu.com/usn/USN-2812-1 | View |
751892 | 85218 | CVE-2015-7941 | BID:74241 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
10585 | JVNDB-2015-005905 | SAP HANA DB の Extended Application Services における任意のコードを実行される脆弱性 | SAP HANA DB の Extended Application Services (別名 XS または XS Engine) には、任意のコードを実行される脆弱性が存在します。 | CVE-2015-7993 | 85218 | 7.5 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-005905.html | View |