CVE-2015-1819

Impact:
Low
Public Date:
2015-04-14
Bugzilla:
1211278: CVE-2015-1819 libxml2: denial of service processing a crafted XML document
A denial of service flaw was found in the way the libxml2 library parsed certain XML files. An attacker could provide a specially crafted XML file that, when parsed by an application using libxml2, could cause that application to use an excessive amount of memory.

Find out more about CVE-2015-1819 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw in libxml2.

CVSS v2 metrics

Base Score 2.6
Base Metrics AV:N/AC:H/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (libxml2) RHSA-2015:2550 2015-12-07
Red Hat Enterprise Linux 6 (libxml2) RHSA-2015:1419 2015-07-20

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 5 libxml2 Will not fix

Acknowledgements

This issue was discovered by Florian Weimer (Red Hat Product Security).
Last Modified