Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9318

Опубликовано: 16 нояб. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

2.9.4+dfsg1-6.1ubuntu1.2
devel

released

2.9.4+dfsg1-7ubuntu1
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.13
esm-infra/bionic

released

2.9.4+dfsg1-6.1ubuntu1.2
esm-infra/xenial

released

2.9.3+dfsg1-1ubuntu0.6
precise

ignored

end of life
precise/esm

not-affected

2.7.8.dfsg-5.1ubuntu4.21
trusty

released

2.9.1+dfsg1-3ubuntu4.13
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.13

Показывать по

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
больше 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
nvd
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
debian
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and ot ...

suse-cvrf
больше 6 лет назад

Security update for libxml2

suse-cvrf
около 9 лет назад

Security update for libxml2

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3