Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3660

Опубликовано: 04 нояб. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

РелизСтатусПримечание
devel

released

2.9.1+dfsg1-4ubuntu1
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.4
lucid

released

2.7.6.dfsg-1ubuntu1.15
precise

released

2.7.8.dfsg-5.1ubuntu4.11
trusty

released

2.9.1+dfsg1-3ubuntu4.4
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.4
upstream

released

2.9.2
utopic

released

2.9.1+dfsg1-4ubuntu1

Показывать по

EPSS

Процентиль: 89%
0.04812
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

nvd
почти 11 лет назад

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

debian
почти 11 лет назад

parser.c in libxml2 before 2.9.2 does not properly prevent entity expa ...

github
больше 3 лет назад

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

oracle-oval
почти 11 лет назад

ELSA-2014-1885: libxml2 security update (MODERATE)

EPSS

Процентиль: 89%
0.04812
Низкий

5 Medium

CVSS2