CVE-2015-1819

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
14/08/2015
Last modified:
12/04/2025

Description

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:* 5.0 (including)
cpe:2.3:a:xmlsoft:libxml:*:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 9.2.1 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.11.3 (including)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 9.1 (including)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools