Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9180

Опубликовано: 22 дек. 2016
Источник: debian

Описание

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml-twig-perlfixed1:3.50-1.1package
libxml-twig-perlno-dsastretchpackage
libxml-twig-perlno-dsajessiepackage
libxml-twig-perlno-dsawheezypackage

Примечания

  • https://rt.cpan.org/Public/Bug/Display.html?id=118097

  • https://bugzilla.redhat.com/show_bug.cgi?id=1379553

  • https://www.openwall.com/lists/oss-security/2016/11/02/1

  • Release 3.50 adds a no_xxe flag which will fail to parse files with external entities.

  • 2016-12-13: The corresponding changes is not in the public git repository yet: https://github.com/mirod/xmltwig/commits/master

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 7.1
redhat
больше 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 9.1
nvd
около 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

suse-cvrf
больше 5 лет назад

Security update for perl-XML-Twig

suse-cvrf
больше 5 лет назад

Security update for perl-XML-Twig