CVE-2015-5312

Modified
Published: 15 Dec 2015, 21:00
Last modified:06 Aug 2024, 06:41

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.1 HIGH
v2.0 (nvd)
EPSS Score
1.08% LOW
1% probability -0.92%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Dec 2015, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 06:41
Last Modified
Vulnerability information updated

Description

The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

CVSS Metrics

  • v2.0HIGHScore: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 1.08% Percentile: 78%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • appleiphone_os

    ≤ 9.2.1

  • applemac_os_x

    ≤ 10.11.3

  • appletvos

    ≤ 9.1

  • applewatchos

    ≤ 2.1

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04 | 15.10

  • debiandebian_linux

    7.0 | 8.0

  • hpicewall_federation_agent

    3.0

  • hpicewall_file_manager

    3.0

  • redhatenterprise_linux_desktop

    6.0

  • redhatenterprise_linux_hpc_node

    6.0

  • redhatenterprise_linux_server

    6.0

  • redhatenterprise_linux_workstation

    6.0

  • xmlsoftlibxml2

    ≤ 2.9.2

References (25)