CVE-2015-7499

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.

References

http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html

http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html

http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html

http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html

http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html

http://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html

http://marc.info/?l=bugtraq&m=145382616617563&w=2

http://rhn.redhat.com/errata/RHSA-2015-2549.html

http://rhn.redhat.com/errata/RHSA-2015-2550.html

http://rhn.redhat.com/errata/RHSA-2016-1089.html

http://www.debian.org/security/2015/dsa-3430

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/79509

http://www.securitytracker.com/id/1034243

http://www.ubuntu.com/usn/USN-2834-1

http://xmlsoft.org/news.html

https://bugzilla.redhat.com/show_bug.cgi?id=1281925

https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfc

https://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0da

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944172

https://security.gentoo.org/glsa/201701-37

https://support.apple.com/HT206166

https://support.apple.com/HT206167

https://support.apple.com/HT206168

https://support.apple.com/HT206169

Details

Source: MITRE

Published: 2015-12-15

Updated: 2019-03-19

Type: CWE-119

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
125603Amazon Linux 2 : libxml2 (ALAS-2019-1220)NessusAmazon Linux Local Security Checks
critical
96541GLSA-201701-37 : libxml2: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
9336Apple TV < 9.2 Multiple VulnerabilitiesNessus Network MonitorInternet Services
critical
9327Mac OS X 10.11.x < 10.11.4 Multiple VulnerabilitiesNessus Network MonitorOperating System Detection
critical
9331Apple iOS < 9.3 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
high
90309Apple TV < 9.2 Multiple VulnerabilitiesNessusMisc.
critical
90118Apple iOS < 9.3 Multiple VulnerabilitiesNessusMobile Devices
critical
90097Mac OS X 10.9.5 / 10.10.5 Multiple Vulnerabilities (Security Update 2016-002)NessusMacOS X Local Security Checks
critical
90096Mac OS X 10.11.x < 10.11.4 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
88742F5 Networks BIG-IP : Multiple libXML2 vulnerabilities (K61570943)NessusF5 Networks Local Security Checks
high
88122openSUSE Security Update : libxml2 (openSUSE-2016-32)NessusSuSE Local Security Checks
high
88019Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : libxml2 vulnerabilities (USN-2875-1)NessusUbuntu Local Security Checks
critical
87865SUSE SLED12 / SLES12 Security Update : libxml2 (SUSE-SU-2016:0049-1)NessusSuSE Local Security Checks
high
87862SUSE SLED11 / SLES11 Security Update : libxml2 (SUSE-SU-2016:0030-1)NessusSuSE Local Security Checks
high
87631openSUSE Security Update : libxml2 (openSUSE-2015-959)NessusSuSE Local Security Checks
high
87608Debian DSA-3430-1 : libxml2 - security updateNessusDebian Local Security Checks
critical
87605Debian DLA-373-1 : libxml2 security updateNessusDebian Local Security Checks
high
87581Scientific Linux Security Update : libxml2 on SL7.x x86_64 (20151207)NessusScientific Linux Local Security Checks
high
87369Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : libxml2 vulnerabilities (USN-2834-1)NessusUbuntu Local Security Checks
high
87354Amazon Linux AMI : libxml2 (ALAS-2015-628)NessusAmazon Linux Local Security Checks
high
87235Scientific Linux Security Update : libxml2 on SL6.x i386/x86_64 (20151207)NessusScientific Linux Local Security Checks
high
87234RHEL 7 : libxml2 (RHSA-2015:2550)NessusRed Hat Local Security Checks
critical
87233RHEL 6 : libxml2 (RHSA-2015:2549)NessusRed Hat Local Security Checks
high
87232OracleVM 3.3 : libxml2 (OVMSA-2015-0152)NessusOracleVM Local Security Checks
high
87231Oracle Linux 7 : libxml2 (ELSA-2015-2550)NessusOracle Linux Local Security Checks
critical
87230Oracle Linux 6 : libxml2 (ELSA-2015-2549)NessusOracle Linux Local Security Checks
high
87224CentOS 7 : libxml2 (CESA-2015:2550)NessusCentOS Local Security Checks
critical
87223CentOS 6 : libxml2 (CESA-2015:2549)NessusCentOS Local Security Checks
high
87000FreeBSD : libxml2 -- multiple vulnerabilities (e5423caf-8fb8-11e5-918c-bcaec565249c)NessusFreeBSD Local Security Checks
high