CVE-2008-3281
published 2008-08-27CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause…
PriorityP423medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.51%
83.0th percentile
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | >= 1.0.0 < 3.0 | 3.0 |
| apple | safari | < 4.0 | 4.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.6.32.dfsg-3 (bookworm) | libxml2 2.6.32.dfsg-3 (bookworm) |
| debian | libxml2 | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Updated ESX packages for libxml2, ucd-snmp, libtiff
vendor_vmware·2008-10-31·CVSS 6.5
CVE-2008-0960 [MEDIUM] Updated ESX packages for libxml2, ucd-snmp, libtiff
VMSA-2008-0017: Updated ESX packages for libxml2, ucd-snmp, libtiff
a. Updated ESX Service Console package libxml2 A denial of service flaw was found in the way libxml2 processes certain content. If an application that is linked against libxml2 processes malformed XML content, the XML content might cause the application to stop responding. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-3281 to this issue. Additionally the following was also fixed, but was missing in the security advisory. A heap-based buffer overflow flaw was found in the way libxml2 handled long XML entity names. If an application linked against libxml2 processed untrusted malformed XML content, it could cause the application to crash or, possibly, execute arbitrary code.
Red Hat
libxml2: infinite loop when entity is used in entity definition
vendor_redhat·2008-10-02·CVSS 6.5
CVE-2008-4409 [MEDIUM] CWE-835 libxml2: infinite loop when entity is used in entity definition
libxml2: infinite loop when entity is used in entity definition
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.
Statement: Not vulnerable. This issue did not affect the versions of libxml2 as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2008-09-11·CVSS 6.5
CVE-2008-3281 [MEDIUM] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: libxml2 vulnerabilities
It was discovered that libxml2 did not correctly handle long entity names.
If a user were tricked into processing a specially crafted XML document,
a remote attacker could execute arbitrary code with user privileges
or cause the application linked against libxml2 to crash, leading to a
denial of service. (CVE-2008-3529)
USN-640-1 fixed vulnerabilities in libxml2. When processing extremely
large XML documents with valid entities, it was possible to incorrectly
trigger the newly added vulnerability protections. This update fixes
the problem. (CVE-2008-3281)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2008-09-03
CVE-2008-3281 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 vulnerability
Andreas Solberg discovered that libxml2 did not handle recursive entities
safely. If an application linked against libxml2 were made to process
a specially crafted XML document, a remote attacker could exhaust the
system's CPU resources, leading to a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
libxml2 denial of service
vendor_redhat·2008-08-20·CVSS 6.5
CVE-2008-3281 [MEDIUM] libxml2 denial of service
libxml2 denial of service
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
Debian
CVE-2008-3281: libxml2 - libxml2 2.6.32 and earlier does not properly detect recursion during entity expa...
vendor_debian·2008·CVSS 6.5
CVE-2008-3281 [MEDIUM] CVE-2008-3281: libxml2 - libxml2 2.6.32 and earlier does not properly detect recursion during entity expa...
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 2.6.32.dfsg-3)
bullseye: resolved (fixed in 2.6.32.dfsg-3)
forky: resolved (fixed in 2.6.32.dfsg-3)
sid: resolved (fixed in 2.6.32.dfsg-3)
trixie: resolved (fixed in 2.6.32.dfsg-3)
Debian
CVE-2008-4409: libxml2 - libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definition...
vendor_debian·2008·CVSS 6.5
CVE-2008-4409 [MEDIUM] CVE-2008-4409: libxml2 - libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definition...
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-34h5-p5c9-pjw6: libxml2 2
ghsa_unreviewed·2022-05-02·CVSS 6.5
CVE-2008-4409 [MEDIUM] GHSA-34h5-p5c9-pjw6: libxml2 2
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.
GHSA
GHSA-x9c5-c5mj-wjjx: libxml2 2
ghsa_unreviewed·2022-05-01
CVE-2008-3281 [MEDIUM] CWE-776 GHSA-x9c5-c5mj-wjjx: libxml2 2
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
OSV
CVE-2008-3281: libxml2 2
osv·2008-08-27·CVSS 6.5
CVE-2008-3281 [MEDIUM] CVE-2008-3281: libxml2 2
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0338 libxml2: CPU consumption DoS when performing string substitutions during entities expansion
bugzilla·2013-02-18·CVSS 6.5
CVE-2013-0338 [MEDIUM] CVE-2013-0338 libxml2: CPU consumption DoS when performing string substitutions during entities expansion
CVE-2013-0338 libxml2: CPU consumption DoS when performing string substitutions during entities expansion
A denial of service flaw was found in the way libxml2, a library providing support to read, modify and write XML and HTML files, performed string substitutions when entity values for entity references replacement (--noent option) was requested / enabled during the XML file parsing. A remote attacker could provide a specially-crafted XML file that, when processed would lead to excessive CPU consumption (denial of service).
Discussion:
This issue affects the versions of the libxml2 package, as shipped with Red Hat Enterprise Linux 5 and 6.
--
This issue affects the versions of the libxml2 package, as shipped with Fedora release of 17 and 18.
--
This issue affects the versions of t
Bugzilla
CVE-2008-4409 libxml2: infinite loop when entity is used in entity definition
bugzilla·2008-10-06·CVSS 6.5
CVE-2008-4409 [MEDIUM] CVE-2008-4409 libxml2: infinite loop when entity is used in entity definition
CVE-2008-4409 libxml2: infinite loop when entity is used in entity definition
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4409 to the following vulnerability:
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities
definitions" in entities, which allows context-dependent attackers to cause a
denial of service (memory consumption and application crash), as demonstrated
by use of xmllint on a certain XML document, a different vulnerability than
CVE-2003-1564 and CVE-2008-3281.
Upstream bugreport:
http://bugzilla.gnome.org/show_bug.cgi?id=554660
Fixed upstream in 2.7.2:
http://mail.gnome.org/archives/xml/2008-October/msg00016.html
References:
http://openwall.com/lists/oss-security/2008/10/02/4
Discussion:
This issue only affected 2.7.x versions of
Bugzilla
CVE-2003-1564 libxml2: billion laughs DoS attack
bugzilla·2008-09-04·CVSS 6.5
CVE-2003-1564 [MEDIUM] CVE-2003-1564 libxml2: billion laughs DoS attack
CVE-2003-1564 libxml2: billion laughs DoS attack
Common Vulnerabilities and Exposures assigned an identifier CVE-2003-1564 to the following vulnerability:
libxml2, possibly before 2.5.0, does not properly detect recursion
during entity expansion, which allows context-dependent attackers to
cause a denial of service (memory and CPU consumption) via a crafted
XML document containing a large number of nested entity references,
aka the "billion laughs attack."
References:
http://www.stylusstudio.com/xmldev/200302/post20020.html
http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2
http://xmlsoft.org/news.html
http://mail.gnome.org/archives/xml/2008-August/msg00034.html
Discussion:
Created attachment 315726
Public test case
Source: http://www.cogsci.ed.ac.uk/~richard/
Bugzilla
CVE-2008-3281 libxml2 denial of service
bugzilla·2008-08-06·CVSS 6.5
CVE-2008-3281 [MEDIUM] CVE-2008-3281 libxml2 denial of service
CVE-2008-3281 libxml2 denial of service
Daniel Veillard discovered that a specially crafted document can lead to a
recursive evaluation of entities, the result being an exhaustion of memory
and CPU usage
Acknowledgements:
Red Hat would like to thank Andreas Solberg for responsibly disclosing this
issue.
Discussion:
I was mistaken,
Andreas Solberg is the discoverer of this flaw.
---
Public now via:
http://mail.gnome.org/archives/xml/2008-August/msg00034.html
---
libxml2-2.6.32-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
libxml2-2.6.32-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
It seems that it introduces s
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000039.htmlhttp://mail.gnome.org/archives/xml/2008-August/msg00034.htmlhttp://secunia.com/advisories/31558http://secunia.com/advisories/31566http://secunia.com/advisories/31590http://secunia.com/advisories/31728http://secunia.com/advisories/31748http://secunia.com/advisories/31855http://secunia.com/advisories/31982http://secunia.com/advisories/32488http://secunia.com/advisories/32807http://secunia.com/advisories/32974http://secunia.com/advisories/35379http://security.gentoo.org/glsa/glsa-200812-06.xmlhttp://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://svn.gnome.org/viewvc/libxml2?view=revision&revision=3772http://wiki.rpath.com/Advisories:rPSA-2008-0325http://www.debian.org/security/2008/dsa-1631http://www.mandriva.com/security/advisories?name=MDVSA-2008:180http://www.mandriva.com/security/advisories?name=MDVSA-2008:192http://www.securityfocus.com/archive/1/497962/100/0/threadedhttp://www.securityfocus.com/bid/30783http://www.securitytracker.com/id?1020728http://www.ubuntu.com/usn/usn-640-1http://www.vmware.com/security/advisories/VMSA-2008-0017.htmlhttp://www.vupen.com/english/advisories/2008/2419http://www.vupen.com/english/advisories/2008/2843http://www.vupen.com/english/advisories/2008/2971http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=458086https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6496https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9812https://rhn.redhat.com/errata/RHSA-2008-0836.htmlhttps://usn.ubuntu.com/644-1/https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00261.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00347.htmlhttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000039.htmlhttp://mail.gnome.org/archives/xml/2008-August/msg00034.htmlhttp://secunia.com/advisories/31558http://secunia.com/advisories/31566http://secunia.com/advisories/31590http://secunia.com/advisories/31728http://secunia.com/advisories/31748http://secunia.com/advisories/31855http://secunia.com/advisories/31982http://secunia.com/advisories/32488http://secunia.com/advisories/32807http://secunia.com/advisories/32974http://secunia.com/advisories/35379http://security.gentoo.org/glsa/glsa-200812-06.xmlhttp://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://svn.gnome.org/viewvc/libxml2?view=revision&revision=3772http://wiki.rpath.com/Advisories:rPSA-2008-0325http://www.debian.org/security/2008/dsa-1631http://www.mandriva.com/security/advisories?name=MDVSA-2008:180http://www.mandriva.com/security/advisories?name=MDVSA-2008:192http://www.securityfocus.com/archive/1/497962/100/0/threadedhttp://www.securityfocus.com/bid/30783http://www.securitytracker.com/id?1020728http://www.ubuntu.com/usn/usn-640-1http://www.vmware.com/security/advisories/VMSA-2008-0017.htmlhttp://www.vupen.com/english/advisories/2008/2419http://www.vupen.com/english/advisories/2008/2843http://www.vupen.com/english/advisories/2008/2971http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=458086https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6496https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9812https://rhn.redhat.com/errata/RHSA-2008-0836.htmlhttps://usn.ubuntu.com/644-1/https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00261.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00347.html
2008-08-27
Published