First published: Fri Aug 28 2015(Updated: )
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
iOS | <=9.2 | |
Apple iOS and macOS | <=10.11.2 | |
tvOS | <=9.1 | |
Apple iOS, iPadOS, and watchOS | <=2.1 | |
libxslt | <=1.1.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7995 has been classified as a medium-severity vulnerability, primarily causing denial of service.
To fix CVE-2015-7995, update libxslt to version 1.1.29 or later if possible.
CVE-2015-7995 affects libxslt versions up to and including 1.1.28, as well as various Apple and Android platforms.
Yes, CVE-2015-7995 can be exploited remotely through a specially crafted XML file.
The impact of CVE-2015-7995 includes potential denial of service due to an unhandled type confusion in the xsltStylePreCompute function.