CVE-2008-3281

Severity
6.5MEDIUM
EPSS
0.8%
top 25.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 1

Description

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

Debianlibxml2< 2.6.32.dfsg-3+3
NVDxmlsoft/libxml22.6.32
NVDapple/safari< 4.0
NVDapple/iphone_os1.0.03.0
NVDvmware/esx4 versions+3

Also affects: Debian Linux 4.0, Fedora 9, Ubuntu Linux 6.06, 7.04, 7.10, 8.04, Enterprise Linux 4.7, 5.2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x9c5-c5mj-wjjx: libxml2 22022-05-01
OSV
CVE-2008-3281: libxml2 22008-08-27
CVEList
CVE-2008-3281: libxml2 22008-08-27

📋Vendor Advisories

5
Red Hat
libxml2: infinite loop when entity is used in entity definition2008-10-02
Ubuntu
libxml2 vulnerabilities2008-09-11
Ubuntu
libxml2 vulnerability2008-09-03
Red Hat
libxml2 denial of service2008-08-20
Debian
CVE-2008-3281: libxml2 - libxml2 2.6.32 and earlier does not properly detect recursion during entity expa...2008

💬Community

2
Bugzilla
CVE-2008-4409 libxml2: infinite loop when entity is used in entity definition2008-10-06
Bugzilla
CVE-2008-3281 libxml2 denial of service2008-08-06
CVE-2008-3281 (MEDIUM CVSS 6.5) | libxml2 2.6.32 and earlier does not | cvebase.io