cbcvebase.
CVE-2021-3541
published 2021-07-09

CVE-2021-3541: A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibxml2< libxml2 2.9.10+dfsg-6.7 (bookworm)libxml2 2.9.10+dfsg-6.7 (bookworm)
nokogirinokogiri>= 0 < 1.11.41.11.4
oraclezfs_storage_appliance_kit
xmlsoftlibxml2< 2.9.112.9.11
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.72.9.10+dfsg-6.7
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.72.9.10+dfsg-6.7
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.72.9.10+dfsg-6.7
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.72.9.10+dfsg-6.7
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-5ubuntu0.20.04.12.9.10+dfsg-5ubuntu0.20.04.1
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm22.9.1+dfsg1-3ubuntu4.13+esm2
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm12.9.3+dfsg1-1ubuntu0.7+esm1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv9.1CRITICAL