PT-2013-1218 · Gentoo Linux+5 · Libxml2+5

Jan Lieskovsky

·

Publicado

2012-11-28

·

Atualizado

2024-06-15

·

CVE-2013-0338

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.9.0 and earlier
Description The issue affects the libxml2 package in Gentoo Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. It can be exploited remotely. Specifically, the problem allows context-dependent attackers to cause a denial of service by consuming CPU and memory resources via a specially crafted XML file. This XML file would contain an entity declaration with long replacement text and many references to this entity, a scenario described as "internal entity expansion" with linear complexity.
Recommendations For libxml2 versions 2.9.0 and earlier, update to version 2.9.1-r1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external XML files to minimize the risk of exploitation. Avoid using the libxml2 package for parsing untrusted XML files until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2345
BDU:2015-09713
CESA-2013_0581
CVE-2013-0338
DSA-2652-1
OPENSUSE-SU-2024:10192-1
RHSA-2013:0581
RHSA-2013_0581
SUSE-SU-2013_0743-1
SUSE-SU-2013_0744-1

Produtos afetados

Alt Linux
Centos
Junos
Red Hat
Suse
Libxml2