The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1819
Reference (s):
- APPLE:APPLE-SA-2016-03-21-1
- URL: http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html
- APPLE:APPLE-SA-2016-03-21-2
- URL: http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
- APPLE:APPLE-SA-2016-03-21-3

