Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000061

Опубликовано: 30 мар. 2017
Источник: redhat
CVSS3: 6.5

Описание

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

It was discovered xmlsec1's use of libxml2 inadvertently enabled external entity expansion (XXE) along with validation. An attacker could craft an XML file that would cause xmlsec1 to try and read local files or HTTP/FTP URLs, leading to information disclosure or denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xmlsec1Will not fix
Red Hat Enterprise Linux 6xmlsec1Will not fix
Red Hat Enterprise Linux 7xmlsec1FixedRHSA-2017:249221.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1437311xmlsec1: xmlsec vulnerable to external entity expansion

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 8 лет назад

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

CVSS3: 7.1
nvd
больше 8 лет назад

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

CVSS3: 7.1
debian
больше 8 лет назад

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansio ...

CVSS3: 7.1
github
больше 3 лет назад

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

oracle-oval
около 8 лет назад

ELSA-2017-2492: xmlsec1 security update (MODERATE)

6.5 Medium

CVSS3