Bug 1277146 (CVE-2015-8035) - CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ decompression
Summary: CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ deco...
Alias: CVE-2015-8035
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1277147 1277149 1277150 Red Hat1322872 Engineering1595697
Blocks: Embargoed1274223 Embargoed1277152 Embargoed1318206
TreeView+ depends on / blocked
Reported: 2015-11-02 13:45 UTC by Adam Mariš
Modified: 2021-02-17 04:45 UTC (History)
21 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to crash.
Clone Of:
Last Closed: 2019-06-08 02:45:04 UTC

Attachments (Terms of Use)
Suggested patch for the issue (501 bytes, patch)
2015-11-02 16:46 UTC, Daniel Veillard
no flags Details | Diff

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:1089 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss Web Server 3.0.3 security update 2016-05-17 20:12:21 UTC
Red Hat Product Errata RHSA-2020:1190 0 None None None 2020-03-31 19:33:25 UTC

Description Adam Mariš 2015-11-02 13:45:30 UTC
A vulnerability in libxml2 when parsing specially crafted XML document if XZ support is enabled causing DoS of application was found.

CVE request (including reproducer):


Comment 1 Adam Mariš 2015-11-02 13:46:11 UTC
Created libxml2 tracking bugs for this issue:

Affects: fedora-all [bug 1277147]

Comment 2 Adam Mariš 2015-11-02 13:46:19 UTC
Created mingw-libxml2 tracking bugs for this issue:

Affects: fedora-all [bug 1277149]
Affects: epel-7 [bug 1277150]

Comment 3 Martin Prpič 2015-11-02 14:16:34 UTC

This issue did not affect the versions of libxml2 as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include support for LZMA compression support.

Comment 4 Martin Prpič 2015-11-02 14:58:21 UTC
LZMA compression support was introduced in libxml2 in:

2.8.0: May 23 2012
Features: add lzma compression support (Anders F Bjorklund)

Comment 5 Daniel Veillard 2015-11-02 16:45:39 UTC
So lzma support in 2.9.2 seems to be broken that's why Fedora seems not affected.

But the bug is present since all version 2.8.0 onward.
Seems I managed to get a first fix for the issue, I will add as attachment


Comment 6 Daniel Veillard 2015-11-02 16:46:28 UTC
Created attachment 1088640 [details]
Suggested patch for the issue

Comment 13 errata-xmlrpc 2016-05-17 16:14:02 UTC
This issue has been addressed in the following products:

Via RHSA-2016:1089 https://rhn.redhat.com/errata/RHSA-2016-1089.html

Comment 14 Matthew Almond 2018-06-26 21:20:30 UTC
Will this bug be addressed in RHEL7.x?

Comment 16 Adam Mariš 2018-06-27 11:56:22 UTC
(In reply to Matthew Almond from comment #14)
> Will this bug be addressed in RHEL7.x?

Thanks for notifying us, this may be fixed in future release.

Comment 17 errata-xmlrpc 2020-03-31 19:33:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:1190 https://access.redhat.com/errata/RHSA-2020:1190

Note You need to log in before you can comment on or make changes to this bug.