PublicDateAtUSN: 2015-08-14 Candidate: CVE-2015-1819 PublicDate: 2015-08-14 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1819 https://ubuntu.com/security/notices/USN-2812-1 Description: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack. Ubuntu-Description: Notes: Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=782782 Priority: low Discovered-by: Florian Weimer Assigned-to: mdeslaur CVSS: Patches_libxml2: upstream: https://git.gnome.org/browse/libxml2/commit/?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9 upstream_libxml2: released (2.9.2+zdfsg1-4) lucid_libxml2: ignored (reached end-of-life) precise_libxml2: released (2.7.8.dfsg-5.1ubuntu4.12) trusty_libxml2: released (2.9.1+dfsg1-3ubuntu4.5) trusty/esm_libxml2: released (2.9.1+dfsg1-3ubuntu4.5) utopic_libxml2: ignored (reached end-of-life) vivid_libxml2: released (2.9.2+dfsg1-3ubuntu0.1) wily_libxml2: not-affected (2.9.2+zdfsg1-4) devel_libxml2: not-affected (2.9.2+zdfsg1-4) vivid/stable-phone-overlay_libxml2: released (2.9.2+dfsg1-3ubuntu0.2) vivid/ubuntu-core_libxml2: DNE