Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libxml2 资源管理错误漏洞
Vulnerability Description
"libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 " libxml2 2.9.6之前版本中的xzlib.c文件的‘xz_head’函数存在安全漏洞,该漏洞源于程序没有对合法文件限制内存的使用。远程攻击者可借助特制的LZMA文件利用该漏洞造成拒绝服务(内存消耗)。
CVSS Information
N/A
Vulnerability Type
N/A