CVE-2015-8317 - Medium Severity Vulnerability
Vulnerable Library - libxml2v2.9.2
XML parser and markup toolkit
Library home page: https://github.com/GNOME/libxml2.git
Found in HEAD commit: e2ecf13c97834779d16859ebddc92a6dcdcb193f
Library Source Files (1)
* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.
Vulnerability Details
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
Publish Date: 2015-12-15
URL: CVE-2015-8317
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2015-8317
Release Date: 2015-12-15
Fix Resolution: 2.9.3
Step up your Open Source Security Game with WhiteSource here
CVE-2015-8317 - Medium Severity Vulnerability
XML parser and markup toolkit
Library home page: https://github.com/GNOME/libxml2.git
Found in HEAD commit: e2ecf13c97834779d16859ebddc92a6dcdcb193f
* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
Publish Date: 2015-12-15
URL: CVE-2015-8317
Base Score Metrics not available
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2015-8317
Release Date: 2015-12-15
Fix Resolution: 2.9.3
Step up your Open Source Security Game with WhiteSource here