Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2003-1564

Опубликовано: 31 дек. 2003
Источник: ubuntu
Приоритет: low
CVSS2: 9.3
CVSS3: 6.5

Описание

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

РелизСтатусПримечание
devel

not-affected

hardy

not-affected

2.6.31.dfsg-2ubuntu1
lucid

not-affected

natty

not-affected

oneiric

not-affected

precise

not-affected

upstream

released

2.5.0

Показывать по

Ссылки на источники

9.3 Critical

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

redhat
больше 22 лет назад

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

CVSS3: 6.5
nvd
почти 22 года назад

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

CVSS3: 6.5
github
больше 3 лет назад

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

fstec
около 17 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

fstec
около 17 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

9.3 Critical

CVSS2

6.5 Medium

CVSS3