The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
CVE-2018-9251 - Medium Severity Vulnerability
Vulnerable Library - https://source.codeaurora.org/quic/la/platform/external/libxml2/LA.UM.6.6.c27-04000-89xx.0
Library home page: https://source.codeaurora.org/quic/la/platform/external/libxml2/
Found in HEAD commit: ebbe518de6103063656cb8a1c3d1040aacb09826
Found in base branch: main
Vulnerable Source Files (1)
dvna/node_modules/libxmljs/vendor/libxml/xzlib.c
Vulnerability Details
The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
Publish Date: 2018-04-04
URL: CVE-2018-9251
CVSS 3 Score Details (5.3)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-9251
Release Date: 2018-04-04
Fix Resolution: v2.9.9-rc1