CVE-2014-0191
published 2015-01-21CVE-2014-0191: The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware…
PriorityP434medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
8.10%
94.2th percentile
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | libxml2 | < libxml2 2.9.1+dfsg1-4 (bookworm) | libxml2 2.9.1+dfsg1-4 (bookworm) |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-4 | 2.9.1+dfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-4 | 2.9.1+dfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-4 | 2.9.1+dfsg1-4 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-4 | 2.9.1+dfsg1-4 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vSphere product updates address security vulnerabilities
vendor_vmware·2014-12-04·CVSS 4.3
CVE-2013-1752 [MEDIUM] VMware vSphere product updates address security vulnerabilities
VMSA-2014-0012: VMware vSphere product updates address security vulnerabilities
a. VMware vCSA cross-site scripting vulnerability VMware vCenter Server Appliance (vCSA) contains a vulnerability that may allow for Cross Site Scripting. Exploitation of this vulnerability in vCenter Server requires tricking a user to click on a malicious link or to open a malicious web page. VMware would like to thank Tanya Secker of Trustwave SpiderLabs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3797 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Pro
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2014-05-15
CVE-2014-0191 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to consume resources if it processed a specially
crafted file.
Daniel Berrange discovered that libxml2 would incorrectly perform entity
substitution even when requested not to. If a user or automated system were
tricked into opening a specially crafted document, an attacker could
possibly cause resource consumption, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libxml2: external parameter entity loaded when entity substitution is disabled
vendor_redhat·2014-05-06·CVSS 4.3
CVE-2014-0191 [MEDIUM] CWE-611 libxml2: external parameter entity loaded when entity substitution is disabled
libxml2: external parameter entity loaded when entity substitution is disabled
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
It was discovered that libxml2 loaded external parameter entities even when entity substitution was disabled. A remote attacker able to provide a specially crafted XML file to an application linked against libxml2 could use this flaw to conduct XML External Entity (XXE) attacks, possibly resulting in
Debian
CVE-2014-0191: libxml2 - The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as ...
vendor_debian·2014·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191: libxml2 - The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as ...
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 2.9.1+dfsg1-4)
bullseye: resolved (fixed in 2.9.1+dfsg1-4)
forky: resolved (fixed in 2.9.1+dfsg1-4)
sid: resolved (fixed in 2.9.1+dfsg1-4)
trixie: resolved (fixed in 2.9.1+dfsg1-4)
Apple
CVE-2014-0191: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-0191
Component: CVE-ID
Impact: Parsing a maliciously crafted XML document may lead to disclosure of user information
Description: A memory access issue existed in libxml2. This was addressed by improved memory handling
Apple
CVE-2014-0191: iOS 8.4.1
vendor_apple·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2014-0191
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue existed in handling of malformed XPC messages. This issue was improved through improved bounds checking.
Apple
CVE-2014-0191: Apple TV 7.2.1
vendor_apple·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2014-0191
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue existed in handling of malformed XPC messages. This issue was improved through improved bounds checking.
GHSA
GHSA-hwp3-c628-9f7v: The xmlParserHandlePEReference function in parser
ghsa_unreviewed·2022-05-17
CVE-2014-0191 [MEDIUM] GHSA-hwp3-c628-9f7v: The xmlParserHandlePEReference function in parser
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
GHSA
GHSA-39pv-g7w9-q7vv: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2015-0386 [MEDIUM] GHSA-39pv-g7w9-q7vv: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2013-0338, CVE-2013-2877, and CVE-2014-0191.
OSV
CVE-2014-0191: The xmlParserHandlePEReference function in parser
osv·2015-01-21·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191: The xmlParserHandlePEReference function in parser
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
No detection rules found.
Bugzilla
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [epel-7]
bugzilla·2015-02-11·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [epel-7]
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 track
Bugzilla
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
bugzilla·2015-01-05·CVSS 7.5
CVE-2012-6685 [HIGH] CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
CVE-2012-6685 rubygem-nokogiri: XML eXternal Entity (XXE) flaw
An XML eXternal Entity (XXE) flaw was found in Nokogiri, a Ruby gem for parsing HTML, XML, and SAX. Using external XML entities, a remote attacker could specify a URL in a specially crafted XML that, when parsed, would cause a connection to that URL to be opened.
A patch shipped with the 1.5.4 release of Nokogiri provided a "nonet" option to disable external connections. However, local file URLs could still be used to exploit this flaw. The 1.6.4 release of Nokogiri fixed this issue by using libxml2 2.9.0.
Additional information is detailed at:
https://github.com/sparklemotion/nokogiri/issues/693#issuecomment-68334768
CVE request and assignment:
http://seclists.org/oss-sec/2015/q1/57
Discussion:
Created rubygem-nokogiri
Bugzilla
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
bugzilla·2014-06-10·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE:
Bugzilla
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
bugzilla·2014-06-10·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
CVE-2014-0191 mingw-libxml2: libxml2: external parameter entity loaded when entity substitution is disabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
Bugzilla
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled
bugzilla·2014-04-24·CVSS 4.3
CVE-2014-0191 [MEDIUM] CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled
CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled
It was discovered that libxml2, a library providing support to read, modify and write XML files, incorrectly performs entity substituton in the doctype prolog, even if the application using libxml2 disabled any entity substitution. A remote attacker could provide a specially-crafted XML file that, when processed, would lead to the exhaustion of CPU and memory resources or file descriptors.
Discussion:
Acknowledgements:
This issue was discovered by Daniel P. Berrange of Red Hat.
---
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df
---
Public via:
http://www.openwall.com/lists/oss-security/2014/05/06/4
---
This issue is related to the
Bugzilla
CVE-2013-0339 libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
bugzilla·2013-02-25·CVSS 4.3
CVE-2013-0339 [MEDIUM] CVE-2013-0339 libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
CVE-2013-0339 libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
A denial of service flaw was found in the way libxml2, a library providing support to read, modify and write XML and HTML files, performed string substitutions when entity values for external entity references replacement (--noent option) was requested / enabled during the XML file parsing. A remote attacker could provide a specially-crafted XML file containing an external entity expansion, when processed would lead to excessive CPU consumption (denial of service).
This a different flaw from CVE-2013-0338.
Upstream patch:
http://git.gnome.org/browse/libxml2/commit/?id=23f05e0c33987d6605387b300c4be5da2120a7ab
Discussion:
Reference:
http://seclists.org/o
arXiv
Shelving it rather than Ditching it: Dynamically Debloating DEX and Native Methods of Android Applications without APK Modification
arxiv_fulltext·2025-01-09
Shelving it rather than Ditching it: Dynamically Debloating DEX and Native Methods of Android Applications without APK Modification
Shelving it rather than Ditching it: Dynamically Debloating DEX and Native Methods of Android Applications without APK Modification
Zicheng Zhang
Singapore Management University
Singapore, Singapore
[email protected]
Jiakun Liu
Singapore Management University
Singapore, Singapore
[email protected]
Ferdian Thung
Singapore Management University
Singapore, Singapore
[email protected]
Haoyu Ma
Zhejiang Lab
Hangzhou, China
[email protected]
Rui Li
Singapore Management University
Singapore, Singapore
[email protected]
Yan Naing Tun
Singapore Management University
Singapore, Singapore
[email protected]
Wei Minn
Singapore Management University
Singapore, Singapore
[email protected]
Lwin Khin Shar
Singapore Management University
Singapore,
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0749.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21678183http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/67233http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1090976https://exchange.xforce.ibmcloud.com/vulnerabilities/93092https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854dfhttps://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0749.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21678183http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/67233http://xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1090976https://exchange.xforce.ibmcloud.com/vulnerabilities/93092https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854dfhttps://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031
2015-01-21
Published