CVE-2011-2188Luaexpat vulnerability

6 documents5 sources
Severity
5.0MEDIUMNVD
OSV6.5
EPSS
1.2%
top 21.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateMay 17

Description

LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

debiandebian/lua-expat< lua-expat 1.2.0-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-827g-rqf3-jrp6: LuaExpat before 12022-05-17
OSV
CVE-2011-2188: LuaExpat before 12011-06-21

📋Vendor Advisories

1
Debian
CVE-2011-2188: lua-expat - LuaExpat before 1.2.0 does not properly detect recursion during entity expansion...2011

💬Community

2
Bugzilla
CVE-2011-2188 lua-expat: Prone to XML "billion laughs attack" [fedora-13]2011-06-06
Bugzilla
CVE-2011-2188 lua-expat: Prone to XML "billion laughs attack"2011-06-06
CVE-2011-2188 — Matthewwild Luaexpat vulnerability | cvebase