CVE-2015-7497: Buffer Overflow
A heap-based buffer overflow vulnerability was found in xmlDictComputeFastQKey in dict.c.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=756528
Other sources
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7497?
CVE-2015-7497 is classified as a high severity vulnerability due to the potential for remote code execution caused by the heap-based buffer overflow.
How do I fix CVE-2015-7497?
To fix CVE-2015-7497, update the affected libxml2 package to version 2.9.3 or later, which resolves the buffer overflow issue.
Which software is affected by CVE-2015-7497?
CVE-2015-7497 affects various distributions including Debian 7.0, Debian 8.0, Ubuntu 12.04, 14.04, 15.04, and 15.10, as well as Red Hat Enterprise Linux 6.0.
What is the impact of CVE-2015-7497?
The impact of CVE-2015-7497 could potentially allow an attacker to exploit the vulnerability to execute arbitrary code on the affected systems.
When was CVE-2015-7497 reported?
CVE-2015-7497 was reported in 2015 and is associated with the function xmlDictComputeFastQKey in the libxml2 library.