CVE-2015-7497

Published Dec 15, 2015

Last updated 19 days ago

Overview

Description
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
Source
secalert@redhat.com
NVD status
Modified
Products
debian_linux, ubuntu_linux, libxml2, enterprise_linux_desktop, enterprise_linux_hpc_node, enterprise_linux_server, enterprise_linux_workstation, icewall_federation_agent, icewall_file_manager

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.