Описание
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.9.3+dfsg1-1.2 |
esm-infra-legacy/trusty | released | 2.9.1+dfsg1-3ubuntu4.8 |
esm-infra/xenial | released | 2.9.3+dfsg1-1ubuntu0.1 |
precise | released | 2.7.8.dfsg-5.1ubuntu4.15 |
precise/esm | not-affected | 2.7.8.dfsg-5.1ubuntu4.15 |
trusty | released | 2.9.1+dfsg1-3ubuntu4.8 |
trusty/esm | released | 2.9.1+dfsg1-3ubuntu4.8 |
upstream | released | 2.9.4 |
vivid/stable-phone-overlay | ignored | end of life |
vivid/ubuntu-core | DNE |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions ...
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
Уязвимость функций xmlParserEntityCheck и xmlParseAttValueComplex библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2
7.5 High
CVSS3