Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9180

Опубликовано: 27 сент. 2016
Источник: redhat
CVSS3: 7.1
CVSS2: 5.8

Описание

perl-XML-Twig: The option to expand_external_ents, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

A vulnerability was found in perl-XML-Twig. External entity expansion (XXE) took place regardless of the setting 'expand_external_ents', which was supposed to disable this functionality if set to 0 (the default) or -1. An attacker could craft an XML message which, when processed by an application using perl-XML-Twig, could cause denial of service or, potentially, information disclosure.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perl-XML-TwigWill not fix
Red Hat Enterprise Linux 6perl-XML-TwigWill not fix
Red Hat Enterprise Linux 7perl-XML-TwigWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1379553perl-XML-Twig: expand_external_ents option fails to work as documented

7.1 High

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 9.1
nvd
около 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 9.1
debian
около 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as con ...

suse-cvrf
больше 5 лет назад

Security update for perl-XML-Twig

suse-cvrf
больше 5 лет назад

Security update for perl-XML-Twig

7.1 High

CVSS3

5.8 Medium

CVSS2