Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3451

Опубликовано: 23 апр. 2015
Источник: redhat
CVSS2: 2.6

Описание

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

Отчет

This issue affects the versions of perl-XML-LibXML as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

This issue only affects programs using this program in forms such as: $parser = XML::LibXML->new or $XML_DOC = $parser->load_xml if you use the form: $XML_DOC = XML::LibXML->load_xml this vulnerability will not be exposed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perl-XML-LibXMLWill not fix
Red Hat Enterprise Linux 6perl-XML-LibXMLWill not fix
Red Hat Enterprise Linux 7perl-XML-LibXMLWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1216112perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

nvd
больше 10 лет назад

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

debian
больше 10 лет назад

The _clone function in XML::LibXML before 2.0119 does not properly set ...

suse-cvrf
больше 10 лет назад

Security update for perl-XML-LibXML

github
больше 3 лет назад

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

2.6 Low

CVSS2

Уязвимость CVE-2015-3451