Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)
Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)
Release date:
Updated on:
Affected Systems:
Libxml libxml2 <2.9.3
Description:
CVE (CAN) ID: CVE-2015-8317
Libxml2 is an XML Parser and markup tool set.
Versions earlier than libxml2 2.9.3, parser. the xmlParseXMLDecl function in c has a security vulnerability. The XML data does not have an ending encoding value or an incomplete XML declaration triggers cross-border heap reading, attackers with independent context can exploit this vulnerability to obtain sensitive information.
<* Source: Hanno Boeck (hanno@hboeck.de)
*>
Suggestion:
Vendor patch:
Libxml
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.gnome.org/show_bug.cgi? Id = 751603
Https://git.gnome.org/browse/libxml2/commit? Id = 9aa37588ee78a06ca1379a9d9356eab16686099c
Http://rhn.redhat.com/errata/RHSA-2015-2549.html
Upgrade Linux built-in libxml2 library install php-5.2.5 on RedHat Linux
Ubuntu libxml2
Use of Libxml2 in Linux
Use arm-none-linux-gnueabi in Ubuntu to cross-compile libxml2
Install and use libxml2 in Ubuntu 14.04
This article permanently updates the link address: