The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
2018-04-04T02:29:00.320
2024-11-21T04:15:13.273
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:N/A:P
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xmlsoft | libxml2 | 2.9.8 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |