CVE-2017-18258
libxml2: Unrestricted memory usage in xz_head() function in xzlib.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
La función xz_head en xzlib.c en libxml2, en versiones anteriores a la 2.9.6, permite que atacantes remotos provoquen una denegación de servicio (consumo de memoria) mediante un archivo LZMA. Esto se dene a que la funcionalidad de descifrado no restringe el uso de memoria a lo que se requiere para un archivo legítimo.
The libxml2 library is a development toolbox providing the implementation of various XML standards. Issues addressed include denial of service and null pointer vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-08 CVE Reserved
- 2018-04-08 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10284 | X_refsource_confirm | |
https://lists.debian.org/debian-lts-announce/2018/09/msg00035.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2020/09/msg00009.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20190719-0001 | X_refsource_confirm |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://git.gnome.org/browse/libxml2/commit/?id=e2a9122b8dde53d320750451e9907a7dcb2ca8bb | 2020-09-10 |
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3739-1 | 2020-09-10 | |
https://access.redhat.com/security/cve/CVE-2017-18258 | 2020-03-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1566749 | 2020-03-31 |