CVE-2015-7995 PUBLISHED

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

EPSS 1.41% · 80.4th percentile

Risk Scores

EPSS Score
1.41%
80.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxslt0, 1.1.28-2, 1.1.28-2build1

Timeline

References

Open in Interactive Console →