CVE-2015-1283

Description

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.521

Associated Vulnerability

VulnerabilityOS Platform
Update for Google Chrome (44.0.2403.89)Windows
Update for Google Chrome x64 (44.0.2403.89)Windows
Updates for Google Chrome (66.0.3359.170)Windows
Updates for Google Chrome (x64) (66.0.3359.170)Windows
Updates for Google Chrome (66.0.3359.181)Windows
Updates for Google Chrome (x64) (66.0.3359.181)Windows
Updates for Google Chrome (67.0.3396.62)Windows
Updates for Google Chrome (x64) (67.0.3396.62)Windows
Updates for Google Chrome (67.0.3396.79)Windows
Updates for Google Chrome (x64) (67.0.3396.79)Windows
Updates for Google Chrome (67.0.3396.87)Windows
Updates for Google Chrome (x64) (67.0.3396.87)Windows
Google Chrome (67.0.3396.99)Windows
Google Chrome (x64) (67.0.3396.99)Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.7Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.12Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.9Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.33Windows
Multiple vulnerabilities are fixed in IBM HTTP 6.1.0.47Windows
Vulnerabilities CVE-2015-4947,CVE-2015-2716,CVE-2015-1283 are fixed in IBM HTTP 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.39Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.23Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.30Windows
Multiple vulnerabilities are fixed in Update for Google Chrome For Mac (44.0.2403.89)Mac
XML parsing C library (USN-2726-1) libexpat1_2.1.0-4ubuntu1.1_i386.debLinux
XML parsing C library (USN-2726-1) libexpat1_2.1.0-4ubuntu1.1_amd64.debLinux
XML parsing C library (USN-2726-1) libexpat1_2.1.0-6ubuntu1.1_i386.debLinux
XML parsing C library (USN-2726-1) libexpat1_2.1.0-6ubuntu1.1_amd64.debLinux
XML parsing C library (USN-2726-1) lib64expat1_2.1.0-4ubuntu1.1_i386.debLinux
XML parsing C library (USN-2726-1) lib64expat1_2.1.0-6ubuntu1.1_i386.debLinux
Lightweight RPC library based on XML and HTTP (USN-3013-1) libxmlrpc-c++4_1.16.33-3.1ubuntu5.2_i386.debLinux
Lightweight RPC library based on XML and HTTP (USN-3013-1) libxmlrpc-c++4_1.16.33-3.1ubuntu5.2_amd64.debLinux
Lightweight RPC library based on XML and HTTP (USN-3013-1) libxmlrpc-core-c3_1.16.33-3.1ubuntu5.2_i386.debLinux
Lightweight RPC library based on XML and HTTP (USN-3013-1) libxmlrpc-core-c3_1.16.33-3.1ubuntu5.2_amd64.debLinux
expat security update(DSA-3318-1) expat_2.1.0-1+deb7u2_i386.debLinux
expat security update(DSA-3597-1) expat_2.1.0-6+deb8u3_i386.debLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) expat-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) expat-debuginfo-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) expat-debuginfo-32bit-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) expat-debugsource-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) libexpat1-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) libexpat1-32bit-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) libexpat1-debuginfo-2.1.0-17.1.x86_64.rpmLinux
SUSE-SU-2016:1508-1(SUSE Linux Enterprise Desktop 12 ) libexpat1-debuginfo-32bit-2.1.0-17.1.x86_64.rpmLinux
Update for Google Chrome (44.0.2403.89) (For Ubuntu)Linux
Updates for Google Chrome (66.0.3359.170) (For Ubuntu)Linux
Update for Google Chrome (44.0.2403.89) (For Debian)Linux
Updates for Google Chrome (66.0.3359.170) (For Debian)Linux
Updates for Google Chrome (66.0.3359.181) (For Debian)Linux
Updates for Google Chrome (67.0.3396.62) (For Debian)Linux
Updates for Google Chrome (67.0.3396.79) (For Debian)Linux
Updates for Google Chrome (67.0.3396.87) (For Debian)Linux
Google Chrome (67.0.3396.99) (For Debian)Linux
Update for Google Chrome (44.0.2403.89) (For Centos)Linux
Updates for Google Chrome (66.0.3359.170) (For Centos)Linux
Updates for Google Chrome (66.0.3359.181) (For Centos)Linux
Updates for Google Chrome (67.0.3396.62) (For Centos)Linux
Updates for Google Chrome (67.0.3396.79) (For Centos)Linux
Updates for Google Chrome (67.0.3396.87) (For Centos)Linux
Google Chrome (67.0.3396.99) (For Centos)Linux
Update for Google Chrome (44.0.2403.89) (For RedHat)Linux
Updates for Google Chrome (66.0.3359.170) (For RedHat)Linux
Updates for Google Chrome (66.0.3359.181) (For RedHat)Linux
Updates for Google Chrome (67.0.3396.62) (For RedHat)Linux
Updates for Google Chrome (67.0.3396.79) (For RedHat)Linux
Updates for Google Chrome (67.0.3396.87) (For RedHat)Linux
Google Chrome (67.0.3396.99) (For RedHat)Linux
Update for Google Chrome (44.0.2403.89) (For Suse)Linux
Updates for Google Chrome (66.0.3359.170) (For Suse)Linux
Updates for Google Chrome (66.0.3359.181) (For Suse)Linux
Updates for Google Chrome (67.0.3396.62) (For Suse)Linux
Updates for Google Chrome (67.0.3396.79) (For Suse)Linux
Updates for Google Chrome (67.0.3396.87) (For Suse)Linux
Google Chrome (67.0.3396.99) (For Suse)Linux
Updates for Google Chrome (66.0.3359.181) (For Ubuntu)Linux
Updates for Google Chrome (67.0.3396.62) (For Ubuntu)Linux
Updates for Google Chrome (67.0.3396.79) (For Ubuntu)Linux
Updates for Google Chrome (67.0.3396.87) (For Ubuntu)Linux
Google Chrome (67.0.3396.99) (For Ubuntu)Linux
XML Parser Toolkit, runtime libraries (USN-7199-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
library for rendering vector based animations and art (USN-7198-1) libxmltok1t64_1.2-4.1ubuntu3.1_amd64.debLinux
Integer Overflow or Wraparound Vulnerability (CVE-2015-1283)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-302132Update for Google Chrome x64 (44.0.2403.89)
PATCH-307513Updates for Google Chrome (66.0.3359.170)
PATCH-307515Updates for Google Chrome (x64) (66.0.3359.170)
PATCH-307534Updates for Google Chrome (66.0.3359.181)
PATCH-307535Updates for Google Chrome (x64) (66.0.3359.181)
PATCH-307607Updates for Google Chrome (67.0.3396.62)
PATCH-307608Updates for Google Chrome (x64) (67.0.3396.62)
PATCH-307641Updates for Google Chrome (67.0.3396.79)
PATCH-307644Updates for Google Chrome (x64) (67.0.3396.79)
PATCH-307660Updates for Google Chrome (67.0.3396.87)
PATCH-307662Updates for Google Chrome (x64) (67.0.3396.87)
PATCH-307715Google Chrome (67.0.3396.99)
PATCH-307716Google Chrome (x64) (67.0.3396.99)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234