Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000190

Опубликовано: 17 нояб. 2017
Источник: debian

Описание

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simple-xmlfixed2.7.1-3package
simple-xmlignoredstretchpackage
simple-xmlno-dsajessiepackage
simple-xmlno-dsawheezypackage

Примечания

  • https://github.com/ngallagher/simplexml/issues/18

  • Fixing commit in a new fork of the library (which is renamed simple-xml-safe):

  • https://github.com/dweiss/simplexml/commit/c8d4b4310549bfaf6dc0a20abea7fbcca6e51edd

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 8 лет назад

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

CVSS3: 9.1
nvd
около 8 лет назад

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

CVSS3: 9.1
github
больше 3 лет назад

SimpleXML has XML External Entity (XXE) vulnerability