CVE-2015-8035

low
Published 2015-11-18 · Modified 2026-05-06
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8035

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://xmlsoft.org/news.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-8035.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2.9.3+dfsg1-1
debian debianbullseyefixed2.9.3+dfsg1-1
debian debianforkyfixed2.9.3+dfsg1-1
debian debiansidfixed2.9.3+dfsg1-1
debian debiantrixiefixed2.9.3+dfsg1-1
debian debian7.0affected
debian debian8.0affected
ubuntu ubuntu14.04affected
macos macosaffected

Application impact

VendorProductVersionsFixed
xmlsoftlibxml22.9.1

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.