PublicDateAtUSN: 2015-10-23 Candidate: CVE-2015-7941 PublicDate: 2015-11-18 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7941 http://www.openwall.com/lists/oss-security/2015/04/19/5 http://www.openwall.com/lists/oss-security/2015/10/22/5 https://ubuntu.com/security/notices/USN-2812-1 Description: libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783010 https://bugzilla.gnome.org/show_bug.cgi?id=744980 Priority: medium Discovered-by: Michal Zalewski Assigned-to: mdeslaur CVSS: Patches_libxml2: upstream: https://git.gnome.org/browse/libxml2/commit/?id=a7dfab7411cbf545f359dd3157e5df1eb0e7ce31 upstream: https://git.gnome.org/browse/libxml2/commit/?id=9b8512337d14c8ddf662fcb98b0135f225a1c489 upstream_libxml2: released (2.9.2+really2.9.1+dfsg1-0.1) precise_libxml2: released (2.7.8.dfsg-5.1ubuntu4.12) trusty_libxml2: released (2.9.1+dfsg1-3ubuntu4.5) trusty/esm_libxml2: released (2.9.1+dfsg1-3ubuntu4.5) vivid_libxml2: released (2.9.2+dfsg1-3ubuntu0.1) wily_libxml2: not-affected (2.9.2+zdfsg1-4) devel_libxml2: not-affected (2.9.2+zdfsg1-4) vivid/stable-phone-overlay_libxml2: released (2.9.2+dfsg1-3ubuntu0.2) vivid/ubuntu-core_libxml2: DNE