Back

MEDIUM

libxml2: Infinite loop caused by incorrect error detection during LZMA decompression

Published Aug 16, 2018

Description

libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this flaw as having Low impact. A future update may address this issue.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 16, 2018
Updated Aug 5, 2024
Reserved Jul 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 3, 2018