CVE-2015-1819: XEE
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1819?
CVE-2015-1819 has been rated as a medium severity vulnerability.
How do I fix CVE-2015-1819?
To fix CVE-2015-1819, update the affected versions of the libxml2 library and any dependent software to the latest releases.
What types of attacks does CVE-2015-1819 enable?
CVE-2015-1819 allows remote attackers to perform denial of service attacks through crafted XML data.
Which software is affected by CVE-2015-1819?
CVE-2015-1819 affects several software packages including libxml2 and various Linux distributions like Debian and Ubuntu.
What is an XML Entity Expansion attack related to CVE-2015-1819?
An XML Entity Expansion attack is a type of denial of service attack that exploits the XML parser's handling of deeply nested entities, leading to excessive memory consumption.