The xz_decomp function in xzlib.c in libxml2 2.9.8, if –with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libxml2 | Xmlsoft | 2.9.8 (including) | 2.9.8 (including) |
Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-7.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-7.el8 | * |
Libxml2 | Ubuntu | upstream | * |