CVE-2015-8035

NameCVE-2015-8035
DescriptionThe xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3430-1
NVD severitylow (attack range: remote)
Debian Bugs803942

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libxml2 (PTS)wheezy2.8.0+dfsg1-7+wheezy5fixed
wheezy (security)2.8.0+dfsg1-7+wheezy11fixed
jessie (security), jessie2.9.1+dfsg1-5+deb8u5fixed
stretch (security), stretch2.9.4+dfsg1-2.2+deb9u1fixed
buster2.9.4+dfsg1-5.1fixed
sid2.9.4+dfsg1-5.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libxml2source(unstable)2.9.3+dfsg1-1low803942
libxml2sourcejessie2.9.1+dfsg1-5+deb8u1lowDSA-3430-1
libxml2sourcesqueeze(not affected)
libxml2sourcewheezy2.8.0+dfsg1-7+wheezy5lowDSA-3430-1

Notes

[squeeze] - libxml2 <not-affected> (No LZMA/XZ support in version 2.7.8)
Upstream patch: https://git.gnome.org/browse/libxml2/commit/?id=f0709e3ca8f8947f2d91ed34e92e38a4c23eae63 (v2.9.3)
You can use "xmllint --version" to verify if libxml2 is compiled with "Lzma" support.
sid's 2.9.2+zdfsg1-4 claims to have "Lzma" support but it's broken in fact...
so it barfs on the problematic file (parser error : Start tag expected,
'<' not found) even though it does not have the fix yet. The next upstream
release will fix this issue and will restore XZ support.
http://www.openwall.com/lists/oss-security/2015/11/02/2

Search for package or bug name: Reporting problems