Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9318

Опубликовано: 06 окт. 2016
Источник: redhat
CVSS3: 6.7
CVSS2: 5.8

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Меры по смягчению последствий

Application parsing untrusted input with libxml2 should be careful to NOT use entity expansion (enabled by XML_PARSE_NOENT) or DTD validation (XML_PARSE_DTDLOAD, XML_PARSE_DTDVALID) on such input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Will not fix
Red Hat Enterprise Linux 6libxml2Will not fix
Red Hat Enterprise Linux 7libxml2Will not fix
Red Hat JBoss Core ServiceshttpdAffected
Text-Only JBCSFixedRHSA-2018:248616.08.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1395609libxml2: XML External Entity vulnerability

6.7 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
nvd
почти 10 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
debian
почти 10 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and ot ...

suse-cvrf
около 7 лет назад

Security update for libxml2

suse-cvrf
больше 9 лет назад

Security update for libxml2

6.7 Medium

CVSS3

5.8 Medium

CVSS2