cbcvebase.
CVE-2013-0339
published 2014-01-21

CVE-2013-0339: libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.

Affected

138 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.8.0+dfsg1-7+nmu1 (bookworm)libxml2 2.8.0+dfsg1-7+nmu1 (bookworm)
suselinux_enterprise_server
xmlsoftlibxml2<= 2.9.1
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2
xmlsoftlibxml2

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM