Описание
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libxml2 | fixed | 2.9.7+dfsg-1 | experimental | package |
| libxml2 | fixed | 2.9.10+dfsg-2 | package | |
| libxml2 | ignored | buster | package | |
| libxml2 | ignored | jessie | package |
Примечания
https://bugzilla.gnome.org/show_bug.cgi?id=759579
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961
Applying only 899a5d9f0ed13b8e32449a08a361e0de127dd961 does not completely
fix the issue, see https://bugs.debian.org/882613#12 for discussion.
bisecting, an important missing patchset seems to be
https://github.com/GNOME/libxml2/commit/453dff1e3b6f7aa724c4996a375c51df6d95abc4
however this patch is very intrusive.
EPSS
Связанные уязвимости
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
Уязвимость компонента parser.c библиотеки Libxml2, позволяющая нарушителю вызвать отказ в обслуживании
EPSS