Vulnerability Description
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | <= 9.2 |
| Apple | Mac Os X | <= 10.11.2 |
| Apple | Tvos | <= 9.1 |
| Apple | Watchos | <= 2.1 |
| Xmlsoft | Libxslt | <= 1.1.28 |
References
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00002.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00003.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00005.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00123.html
- http://www.debian.org/security/2016/dsa-3605
- http://www.openwall.com/lists/oss-security/2015/10/27/10
- http://www.openwall.com/lists/oss-security/2015/10/28/4
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/77325
- http://www.securitytracker.com/id/1034736
- http://www.securitytracker.com/id/1038623
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slack
- https://bugzilla.redhat.com/show_bug.cgi?id=1257962Exploit
- https://git.gnome.org/browse/libxslt/commit/?id=7ca19df892ca22d9314e95d59ce2abde
FAQ
What is CVE-2015-7995?
CVE-2015-7995 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to ...
How severe is CVE-2015-7995?
CVE-2015-7995 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7995?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Iphone Os, Apple Mac Os X, Apple Tvos, Apple Watchos, Xmlsoft Libxslt.