CVE-2015-3451
published 2015-05-12CVE-2015-3451: The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity…
PriorityP434medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.01%
89.4th percentile
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml-libxml-perl | < libxml-libxml-perl 2.0116+dfsg-2 (bookworm) | libxml-libxml-perl 2.0116+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| xml-libxml_project | xml-libxml | <= 2.0118 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
XML::LibXML vulnerability
vendor_ubuntu·2015-05-04
CVE-2015-3451 XML::LibXML vulnerability
Title: XML::LibXML vulnerability
Summary: XML::LibXML could be made to expose sensitive information.
Tilmann Haak discovered that XML::LibXML incorrectly handled the
expand_entities parameter in certain situations. A remote attacker could
possibly use this issue to access sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
vendor_redhat·2015-04-23·CVSS 5.0
CVE-2015-3451 [MEDIUM] CWE-611 perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
perl-XML-LibXML: "expand_entities" option was not preserved under some circumstances
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Statement: This issue affects the versions of perl-XML-LibXML as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Mitigation: This issue only affects programs using this program in forms such as:
$parser = XML::LibXML->new
or
Debian
CVE-2015-3451: libxml-libxml-perl - The _clone function in XML::LibXML before 2.0119 does not properly set the expan...
vendor_debian·2015·CVSS 5.0
CVE-2015-3451 [MEDIUM] CVE-2015-3451: libxml-libxml-perl - The _clone function in XML::LibXML before 2.0119 does not properly set the expan...
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Scope: local
bookworm: resolved (fixed in 2.0116+dfsg-2)
bullseye: resolved (fixed in 2.0116+dfsg-2)
forky: resolved (fixed in 2.0116+dfsg-2)
sid: resolved (fixed in 2.0116+dfsg-2)
trixie: resolved (fixed in 2.0116+dfsg-2)
GHSA
GHSA-mrvg-p24w-mp92: The _clone function in XML::LibXML before 2
ghsa_unreviewed·2022-05-13
CVE-2015-3451 [MEDIUM] CWE-611 GHSA-mrvg-p24w-mp92: The _clone function in XML::LibXML before 2
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
OSV
CVE-2015-3451: The _clone function in XML::LibXML before 2
osv·2015-05-12·CVSS 5.0
CVE-2015-3451 [MEDIUM] CVE-2015-3451: The _clone function in XML::LibXML before 2
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0199.htmlhttp://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changeshttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00006.htmlhttp://www.debian.org/security/2015/dsa-3243http://www.mandriva.com/security/advisories?name=MDVSA-2015:231http://www.openwall.com/lists/oss-security/2015/04/25/2http://www.openwall.com/lists/oss-security/2015/04/30/1http://www.securityfocus.com/bid/74333http://www.ubuntu.com/usn/USN-2592-1https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/http://advisories.mageia.org/MGASA-2015-0199.htmlhttp://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changeshttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00006.htmlhttp://www.debian.org/security/2015/dsa-3243http://www.mandriva.com/security/advisories?name=MDVSA-2015:231http://www.openwall.com/lists/oss-security/2015/04/25/2http://www.openwall.com/lists/oss-security/2015/04/30/1http://www.securityfocus.com/bid/74333http://www.ubuntu.com/usn/USN-2592-1https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/
2015-05-12
Published