CVE-2015-8806: High severity libxml2-devel vulnerability
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8806?
CVE-2015-8806 has been classified as a denial of service vulnerability due to heap-based buffer over-read and application crash.
How do I fix CVE-2015-8806?
To fix CVE-2015-8806, you should upgrade to the patched versions of libxml2 as specified in the security advisories.
What versions of libxml2 are affected by CVE-2015-8806?
CVE-2015-8806 affects versions of libxml2 prior to 2.9.4 and up to 2.9.4+dfsg1-7+deb10u4.
Can CVE-2015-8806 be exploited remotely?
Yes, CVE-2015-8806 can be exploited by remote attackers through crafted HTML documents.
What is the impact of CVE-2015-8806?
The impact of CVE-2015-8806 is a denial of service, causing the application to crash upon processing certain input.