CVE Vulnerabilities

CVE-2015-7995

Published: Nov 17, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a type confusion issue.

Affected Software

NameVendorStart VersionEnd Version
Iphone_osApple*9.2 (including)
Mac_os_xApple*10.11.2 (including)
TvosApple*9.1 (including)
WatchosApple*2.1 (including)
LibxsltUbuntuesm-infra-legacy/trusty*
LibxsltUbuntuprecise*
LibxsltUbuntutrusty*
LibxsltUbuntutrusty/esm*
LibxsltUbuntuupstream*
LibxsltUbuntuvivid*
LibxsltUbuntuwily*

References