CVE-2015-8035: Low severity Debian Debian Linux vulnerability
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.
Other sources
A vulnerability in libxml2 when parsing specially crafted XML document if XZ support is enabled causing DoS of application was found.
CVE request (including reproducer):
http://seclists.org/oss-sec/2015/q4/206
— Red Hat
The xzdecomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2015-8035?
CVE-2015-8035 is classified as a denial of service vulnerability that can cause applications using libxml2 to crash.
How do I fix CVE-2015-8035?
To fix CVE-2015-8035, update your libxml2 package to a version that is not vulnerable, based on your operating system's recommendations.
Which versions of libxml2 are affected by CVE-2015-8035?
CVE-2015-8035 affects libxml2 versions prior to 2.9.1-6.el7.4 and other specific distributions including Debian 7.0 and 8.0.
What type of attack does CVE-2015-8035 enable?
CVE-2015-8035 enables remote attackers to exploit the vulnerability by sending specially crafted XML or HTML files that crash the application.
Is CVE-2015-8035 likely to be exploited in the wild?
While CVE-2015-8035 presents a serious denial of service risk, the likelihood of exploitation depends on the specific application's exposure to untrusted XML or HTML input.