PublicDateAtUSN: 2015-11-26 Candidate: CVE-2015-7499 PublicDate: 2015-12-15 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7499 https://ubuntu.com/security/notices/USN-2834-1 Description: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. Ubuntu-Description: Notes: mdeslaur> USN-2834-1 was missing part of the fix for this issue: mdeslaur> See lp bug Bugs: https://bugzilla.gnome.org/show_bug.cgi?id=756479 https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/1525996 Priority: low Discovered-by: Kostya Serebryany Assigned-to: mdeslaur CVSS: Patches_libxml2: upstream: https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfc upstream: https://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0da upstream: https://git.gnome.org/browse/libxml2/commit/?id=ce0b0d0d81fdbb5f722a890432b52d363e4de57b upstream_libxml2: released (2.9.3) precise_libxml2: released (2.7.8.dfsg-5.1ubuntu4.13) trusty_libxml2: released (2.9.1+dfsg1-3ubuntu4.6) trusty/esm_libxml2: released (2.9.1+dfsg1-3ubuntu4.6) vivid_libxml2: released (2.9.2+dfsg1-3ubuntu0.2) wily_libxml2: released (2.9.2+zdfsg1-4ubuntu0.2) devel_libxml2: released (2.9.2+zdfsg1-4ubuntu2) vivid/stable-phone-overlay_libxml2: released (2.9.2+dfsg1-3ubuntu0.2) vivid/ubuntu-core_libxml2: DNE