libxml2 2.9.8, se si utilizza –with-lzma, consente agli aggressori remoti di causare un denial of service (loop infinito) tramite un file XML artigianale che trigger LZMA_MEMLIMIT_ERROR, come dimostrato da xmllint, una vulnerabilità diverso da quello CVE-2015-8035 e CVE-2018-9251. |
http://www.securityfocus.com/bid/105198 https://gitlab.gnome.org/GNOME/libxml2/commit/2240fbf5912054af025fb6e01e26375100275e74 https://lists.debian.org/debian-lts-announce/2018/09/msg00035.html https://lists.debian.org/debian-lts-announce/2020/09/msg00009.html https://usn.ubuntu.com/3739-1/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14567 |
Vulnerabilità: CVE-2018-14567
