CVE-2018-9251

Source
Severity Medium
Remote Yes
Type Denial of service
Description
A security issue has been found in libxml2 <= 2.9.8 compiled with LZMA support enabled, in the xz_decomp function in xzlib.c. This flaw allows a remote attacker to cause a denial of service via an infinite loop, using a crafted XML payload that triggers LZMA_MEMLIMIT_ERROR.
Group Package Affected Fixed Severity Status Ticket
AVG-673 lib32-libxml2 2.9.8-2 Medium Vulnerable
AVG-672 libxml2 2.9.8-2 Medium Vulnerable
References
https://bugzilla.gnome.org/show_bug.cgi?id=794914