 
        | Release Date: | 2018-08-16 | |
| Impact: | None | What is this? | 
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
See more information about CVE-2018-14567 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
| Base Score: | 6.5 | 
| Vector String: | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H | 
| Version: | 3.0 | 
| Attack Vector: | Network | 
| Attack Complexity: | Low | 
| Privileges Required: | None | 
| User Interaction: | Required | 
| Scope: | Unchanged | 
| Confidentiality Impact: | None | 
| Integrity Impact: | None | 
| Availability Impact: | High | 
| Platform | Errata | Release Date | 
| Oracle Linux version 7 (libxml2) | ELSA-2020-1190 | 2020-04-06 | 
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: