CVE-2015-7499

Published Dec 15, 2015

Last updated 19 days ago

Overview

Description
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
Source
secalert@redhat.com
NVD status
Modified
Products
iphone_os, mac_os_x, tvos, watchos, ubuntu_linux, enterprise_linux_desktop, enterprise_linux_hpc_node, enterprise_linux_server, enterprise_linux_workstation, icewall_federation_agent, icewall_file_manager, libxml2, debian_linux, leap, opensuse

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.