5
CVSSv2

CVE-2015-7995

Published: 17/11/2015 Updated: 08/03/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows malicious users to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple mac os x

apple watchos

apple tvos

xmlsoft libxslt

Vendor Advisories

Debian Bug report logs - #802971 libxslt: CVE-2015-7995: Type confusion may cause DoS Package: src:libxslt; Maintainer for src:libxslt is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Oct 2015 18:18:02 UTC Severity: important ...
Several security issues were fixed in Libxslt ...
Several vulnerabilities were discovered in libxslt, an XSLT processing runtime library, which could lead to information disclosure or denial-of-service (application crash) against an application using the libxslt library For the stable distribution (jessie), these problems have been fixed in version 1128-2+deb8u1 We recommend that you upgrade y ...
A type confusion vulnerability was discovered in the xsltStylePreCompute() function of libxslt A remote attacker could possibly exploit this flaw to cause an application using libxslt to crash by tricking the application into processing a specially crafted XSLT document ...