Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2015-8035
HistoryNov 18, 2015 - 4:59 p.m.

CVE-2015-8035

2015-11-1816:59:09
Debian Security Bug Tracker
security-tracker.debian.org
19

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.01

Percentile

83.4%

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.01

Percentile

83.4%