Описание
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- PatchVendor Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
Конфигурация 3Версия до 5.0 (включая)
cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:xmlsoft:libxml:*:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Конфигурация 6Версия до 9.2.1 (включая)Версия до 10.11.3 (включая)Версия до 9.1 (включая)Версия до 2.1 (включая)
Одно из
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Конфигурация 7
cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
Конфигурация 8
Одно из
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
Конфигурация 9
Одно из
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02464
Низкий
5 Medium
CVSS2
Дефекты
CWE-399
Связанные уязвимости
ubuntu
около 10 лет назад
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
redhat
больше 10 лет назад
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
debian
около 10 лет назад
The xmlreader in libxml allows remote attackers to cause a denial of s ...
oracle-oval
около 10 лет назад
ELSA-2015-1419: libxml2 security and bug fix update (LOW)
EPSS
Процентиль: 85%
0.02464
Низкий
5 Medium
CVSS2
Дефекты
CWE-399