SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-7942

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via…

MEDIUM 6.8EPSS 4.72%

Does this matter?

Lower severity and a low EPSS score (4.72%). Track it; it rarely justifies an emergency change on its own.

Description

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
4.72% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
hp/icewall federation agent · hp/icewall file manager · debian/debian linux · apple/iphone os · apple/mac os x · apple/tvos · apple/watchos · canonical/ubuntu linux · xmlsoft/libxml2
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.