CVE
- Id
- 85219
- CVE No.
- CVE-2015-7942
- Status
- Candidate
- Description
- The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
- Phase
- Assigned (20151022)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
751893 | 85219 | CVE-2015-7942 | MLIST:[oss-security] 20151022 Crafted xml causes out of bound memory access - Libxml2 | View |
751894 | 85219 | CVE-2015-7942 | URL:http://www.openwall.com/lists/oss-security/2015/10/22/5 | View |
751895 | 85219 | CVE-2015-7942 | MLIST:[oss-security] 20151022 Re: Crafted xml causes out of bound memory access - Libxml2 | View |
751896 | 85219 | CVE-2015-7942 | URL:http://www.openwall.com/lists/oss-security/2015/10/22/8 | View |
751897 | 85219 | CVE-2015-7942 | CONFIRM:https://bugzilla.gnome.org/show_bug.cgi?id=744980#c8 | View |
751898 | 85219 | CVE-2015-7942 | CONFIRM:https://bugzilla.gnome.org/show_bug.cgi?id=756456 | View |
751899 | 85219 | CVE-2015-7942 | CONFIRM:http://xmlsoft.org/news.html | View |
751900 | 85219 | CVE-2015-7942 | CONFIRM:https://support.apple.com/HT206166 | View |
751901 | 85219 | CVE-2015-7942 | CONFIRM:https://support.apple.com/HT206167 | View |
751902 | 85219 | CVE-2015-7942 | CONFIRM:https://support.apple.com/HT206168 | View |
751903 | 85219 | CVE-2015-7942 | CONFIRM:https://support.apple.com/HT206169 | View |
751904 | 85219 | CVE-2015-7942 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172 | View |
751905 | 85219 | CVE-2015-7942 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | View |
751906 | 85219 | CVE-2015-7942 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | View |
751907 | 85219 | CVE-2015-7942 | APPLE:APPLE-SA-2016-03-21-1 | View |
751908 | 85219 | CVE-2015-7942 | URL:http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html | View |
751909 | 85219 | CVE-2015-7942 | APPLE:APPLE-SA-2016-03-21-2 | View |
751910 | 85219 | CVE-2015-7942 | URL:http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html | View |
751911 | 85219 | CVE-2015-7942 | APPLE:APPLE-SA-2016-03-21-3 | View |
751912 | 85219 | CVE-2015-7942 | URL:http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html | View |
751913 | 85219 | CVE-2015-7942 | APPLE:APPLE-SA-2016-03-21-5 | View |
751914 | 85219 | CVE-2015-7942 | URL:http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html | View |
751915 | 85219 | CVE-2015-7942 | DEBIAN:DSA-3430 | View |
751916 | 85219 | CVE-2015-7942 | URL:http://www.debian.org/security/2015/dsa-3430 | View |
751917 | 85219 | CVE-2015-7942 | FEDORA:FEDORA-2016-189a7bf68c | View |
751918 | 85219 | CVE-2015-7942 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177341.html | View |
751919 | 85219 | CVE-2015-7942 | FEDORA:FEDORA-2016-a9ee80b01d | View |
751920 | 85219 | CVE-2015-7942 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177381.html | View |
751921 | 85219 | CVE-2015-7942 | HP:HPSBGN03537 | View |
751922 | 85219 | CVE-2015-7942 | URL:http://marc.info/?l=bugtraq&m=145382616617563&w=2 | View |
751923 | 85219 | CVE-2015-7942 | REDHAT:RHSA-2015:2549 | View |
751924 | 85219 | CVE-2015-7942 | URL:http://rhn.redhat.com/errata/RHSA-2015-2549.html | View |
751925 | 85219 | CVE-2015-7942 | REDHAT:RHSA-2015:2550 | View |
751926 | 85219 | CVE-2015-7942 | URL:http://rhn.redhat.com/errata/RHSA-2015-2550.html | View |
751927 | 85219 | CVE-2015-7942 | REDHAT:RHSA-2016:1089 | View |
751928 | 85219 | CVE-2015-7942 | URL:http://rhn.redhat.com/errata/RHSA-2016-1089.html | View |
751929 | 85219 | CVE-2015-7942 | SUSE:openSUSE-SU-2015:2372 | View |
751930 | 85219 | CVE-2015-7942 | URL:http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html | View |
751931 | 85219 | CVE-2015-7942 | SUSE:openSUSE-SU-2016:0106 | View |
751932 | 85219 | CVE-2015-7942 | URL:http://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html | View |
751933 | 85219 | CVE-2015-7942 | UBUNTU:USN-2812-1 | View |
751934 | 85219 | CVE-2015-7942 | URL:http://www.ubuntu.com/usn/USN-2812-1 | View |
751935 | 85219 | CVE-2015-7942 | BID:79507 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
10586 | JVNDB-2015-005906 | SAP HANA DB の SQL インターフェースにおける任意のコードを実行される脆弱性 | SAP HANA DB の SQL インターフェースには、任意のコードを実行される脆弱性が存在します。 | CVE-2015-7994 | 85219 | 7.5 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-005906.html | View |