Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-281-1 expat security update
Debian DSA Debian DSA DSA-3315-1 chromium-browser security update
Debian DSA Debian DSA DSA-3318-1 expat security update
Debian DSA Debian DSA DSA-3582-1 expat security update
EUVD EUVD EUVD-2015-1424 Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
Ubuntu USN Ubuntu USN USN-2677-1 Oxide vulnerabilities
Ubuntu USN Ubuntu USN USN-2726-1 Expat vulnerability
Ubuntu USN Ubuntu USN USN-3013-1 XML-RPC for C and C++ vulnerabilities
Ubuntu USN Ubuntu USN USN-4772-1 VNC4 vulnerabilities
Ubuntu USN Ubuntu USN USN-5455-1 xmltok library vulnerabilities
Ubuntu USN Ubuntu USN USN-7199-1 xmltok library vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2024-08-06T04:40:17.858Z

Reserved: 2015-01-21T00:00:00

Link: CVE-2015-1283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-07-23T00:59:12.680

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-1283

cve-icon Redhat

Severity : Important

Publid Date: 2015-07-21T00:00:00Z

Links: CVE-2015-1283 - Bugzilla

cve-icon OpenCVE Enrichment

No data.