CVE-2015-1283: Buffer Overflow
Published Jul 23, 2015
·Updated
Last updated 15 January 2025
Other sources
Multiple integer overflows in the XMLGetBuffer function in Expat thro ...
— Debian
Affected Software
29 affected componentsFixes available
Google Android
Google Chrome<=43.0.2357.134
Libexpat Project Libexpat<=2.1.0
Python Python>=2.7.0<2.7.12
Python Python>=3.3.0<3.3.7
Python Python>=3.4.0<3.4.5
Python Python>=3.5.0<3.5.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
SUSE Linux Enterprise Debuginfo=11-sp4
SUSE Studio onsite=1.3
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12-sp1
Oracle Solaris=10
Oracle Solaris=11.3
debian/expat
2.2.10-2+deb11u52.2.10-2+deb11u72.5.0-1+deb12u12.7.1-1
Remediation
Patch Available
Patch Available
Event History
Jul 23, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Nov 7, 2016
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:05 PM
Description
Jan 18, 2025
Data Sourced
via Ubuntu·01:35 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-1283?
CVE-2015-1283 is classified as a medium severity vulnerability primarily affecting Expat and related applications.
2
How do I fix CVE-2015-1283?
To fix CVE-2015-1283, update Expat to version 2.1.1 or higher and ensure all affected software, including Google Chrome, is patched to mitigate the risk.
3
Which software is affected by CVE-2015-1283?
CVE-2015-1283 impacts multiple products including Google Chrome versions below 44.0.2403.89 and Expat versions up to 2.1.0.
4
What type of vulnerability is CVE-2015-1283?
CVE-2015-1283 represents an integer overflow vulnerability leading to potential heap-based buffer overflows and denial of service.
5
Can CVE-2015-1283 be exploited remotely?
Yes, CVE-2015-1283 can be exploited remotely by attackers to trigger a denial of service condition.