CVE-2018-9251: Medium severity Xmlsoft Libxml2 vulnerability
A flaw was found in libxml2 2.9.8. The xzdecomp function in xzlib.c, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMAMEMLIMITERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
Reference: https://bugzilla.gnome.org/showbug.cgi?id=794914
Other sources
The xzdecomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMAMEMLIMITERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 0:2.9.7-7.el8 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.9.9
Event History
Frequently Asked Questions
What is CVE-2018-9251?
CVE-2018-9251 is a vulnerability in libxml2 2.9.8 that allows remote attackers to cause a denial of service via a crafted XML file.
How does CVE-2018-9251 affect libxml2?
CVE-2018-9251 affects libxml2 version 2.9.8.
What is the severity of CVE-2018-9251?
The severity of CVE-2018-9251 is medium with a severity value of 5.3.
How can I fix CVE-2018-9251?
To fix CVE-2018-9251, update libxml2 to version 2.9.9.
Where can I find more information about CVE-2018-9251?
You can find more information about CVE-2018-9251 at the following references: [Link 1](https://access.redhat.com/security/cve/CVE-2015-8035), [Link 2](https://bugzilla.gnome.org/show_bug.cgi?id=794914), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1565320).