CVE-2017-18258

Public on 2020-07-21
Modified on 2020-08-12
Description
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
Severity
Low
CVSS v3 Base Score
3.5
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 libxml2 2020-07-21 16:34 ALAS2-2020-1466
Amazon Linux 1 libxml2 2020-08-10 22:59 ALAS-2020-1415

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
NVD CVSSv2 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
NVD CVSSv3 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H