CVE-2013-0339
published 2014-01-21CVE-2013-0339: libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.61%
88.3th percentile
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
Affected
138 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.8.0+dfsg1-7+nmu1 (bookworm) | libxml2 2.8.0+dfsg1-7+nmu1 (bookworm) |
| suse | linux_enterprise_server | — | — |
| xmlsoft | libxml2 | <= 2.9.1 | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qgp-72gr-jfg9: libxml2 through 2
ghsa_unreviewed·2022-05-05
CVE-2013-0339 [MEDIUM] GHSA-4qgp-72gr-jfg9: libxml2 through 2
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
OSV
CVE-2013-0339: libxml2 through 2
osv·2014-01-21·CVSS 6.8
CVE-2013-0339 [MEDIUM] CVE-2013-0339: libxml2 through 2
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
Ubuntu
libxml2 regression
vendor_ubuntu·2013-07-17·CVSS 6.8
[MEDIUM] libxml2 regression
Title: libxml2 regression
Summary: USN-1904-1 introduced a regression in libxml2.
USN-1904-1 fixed vulnerabilities in libxml2. The update caused a regression
for certain users. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that libxml2 would load XML external entities by default.
If a user or automated system were tricked into opening a specially crafted
document, an attacker could possibly obtain access to arbitrary files or
cause resource consumption. This issue only affected Ubuntu 10.04 LTS,
Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-0339)
It was discovered that libxml2 incorrectly handled documents that end
abruptly. If a user or automated system were tricked into opening a
specially crafted document, an attack
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2013-07-15·CVSS 6.8
CVE-2013-0339 [MEDIUM] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 would load XML external entities by default.
If a user or automated system were tricked into opening a specially crafted
document, an attacker could possibly obtain access to arbitrary files or
cause resource consumption. This issue only affected Ubuntu 10.04 LTS,
Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-0339)
It was discovered that libxml2 incorrectly handled documents that end
abruptly. If a user or automated system were tricked into opening a
specially crafted document, an attacker could possibly cause libxml2 to
crash, resulting in a denial of service. (CVE-2013-2877)
Instructions: After a standard system update you need to reboot your computer to make all
the
Red Hat
libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
vendor_redhat·2013-02-19·CVSS 6.8
CVE-2013-0339 [MEDIUM] libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would nee
Debian
CVE-2013-0339: libxml2 - libxml2 through 2.9.1 does not properly handle external entities expansion unles...
vendor_debian·2013·CVSS 6.8
CVE-2013-0339 [MEDIUM] CVE-2013-0339: libxml2 - libxml2 through 2.9.1 does not properly handle external entities expansion unles...
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
Scope: local
bookworm: resolved (fixed in 2.8.0+dfsg1-7+nmu1)
bullseye: resolved (fixed in 2.8.0+dfsg1-7+
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2013/02/21/24http://openwall.com/lists/oss-security/2013/02/22/3http://seclists.org/oss-sec/2013/q4/182http://seclists.org/oss-sec/2013/q4/184http://seclists.org/oss-sec/2013/q4/188http://secunia.com/advisories/52662http://secunia.com/advisories/54172http://secunia.com/advisories/55568http://www.debian.org/security/2013/dsa-2652http://www.openwall.com/lists/oss-security/2013/04/12/6http://www.ubuntu.com/usn/USN-1904-1http://www.ubuntu.com/usn/USN-1904-2https://bugzilla.redhat.com/show_bug.cgi?id=915149https://git.gnome.org/browse/libxml2/commit/?id=4629ee02ac649c27f9c0cf98ba017c6b5526070fhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2013/02/21/24http://openwall.com/lists/oss-security/2013/02/22/3http://seclists.org/oss-sec/2013/q4/182http://seclists.org/oss-sec/2013/q4/184http://seclists.org/oss-sec/2013/q4/188http://secunia.com/advisories/52662http://secunia.com/advisories/54172http://secunia.com/advisories/55568http://www.debian.org/security/2013/dsa-2652http://www.openwall.com/lists/oss-security/2013/04/12/6http://www.ubuntu.com/usn/USN-1904-1http://www.ubuntu.com/usn/USN-1904-2https://bugzilla.redhat.com/show_bug.cgi?id=915149https://git.gnome.org/browse/libxml2/commit/?id=4629ee02ac649c27f9c0cf98ba017c6b5526070f
2014-01-21
Published