Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9318

Опубликовано: 06 окт. 2016
Источник: redhat
CVSS3: 6.7
CVSS2: 5.8
EPSS Низкий

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Меры по смягчению последствий

Application parsing untrusted input with libxml2 should be careful to NOT use entity expansion (enabled by XML_PARSE_NOENT) or DTD validation (XML_PARSE_DTDLOAD, XML_PARSE_DTDVALID) on such input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Will not fix
Red Hat Enterprise Linux 6libxml2Will not fix
Red Hat Enterprise Linux 7libxml2Will not fix
Red Hat JBoss Core ServiceshttpdAffected
Red Hat JBoss Enterprise Web Server 1libxml2Under investigation
Text-Only JBCSFixedRHSA-2018:248616.08.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1395609libxml2: XML External Entity vulnerability

EPSS

Процентиль: 33%
0.00132
Низкий

6.7 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
nvd
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
debian
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and ot ...

suse-cvrf
больше 6 лет назад

Security update for libxml2

suse-cvrf
около 9 лет назад

Security update for libxml2

EPSS

Процентиль: 33%
0.00132
Низкий

6.7 Medium

CVSS3

5.8 Medium

CVSS2