CVE-2015-5312
Publication date 26 November 2015
Last updated 24 July 2024
Ubuntu priority
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
Status
Package | Ubuntu Release | Status |
---|---|---|
libxml2 | ||
14.04 LTS trusty |
Fixed 2.9.1+dfsg1-3ubuntu4.6
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2834-1
- libxml2 vulnerabilities
- 14 December 2015