CVE-2015-7499: Buffer Overflow
A heap-based buffer overflow was found in xmlGROW allowing the attacker to read the memory out of bounds.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=756479
Other sources
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7499?
CVE-2015-7499 is classified as a high severity vulnerability due to its potential to allow attackers to read sensitive process memory information.
How do I fix CVE-2015-7499?
To fix CVE-2015-7499, upgrade libxml2 to version 2.9.3 or later.
What systems are affected by CVE-2015-7499?
CVE-2015-7499 affects various systems including Apple iPhone OS, Mac OS X, tvOS, watchOS, multiple versions of Ubuntu, Red Hat Enterprise Linux, and certain HP software products.
What type of vulnerability is CVE-2015-7499?
CVE-2015-7499 is a heap-based buffer overflow vulnerability.
Can CVE-2015-7499 be exploited remotely?
Yes, CVE-2015-7499 can be exploited by context-dependent attackers through unspecified vectors.