PT-2013-1219 · Gnome+1 · Libxml2+1

Jonathan Murray

+2

·

Publicado

2013-04-03

·

Atualizado

2022-05-17

·

CVE-2013-1664

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Python versions 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6 libxml2 versions prior to 2.9.1-r1
Description The issue allows remote attackers to cause a denial of service, resulting in resource consumption and crash, via an XML Entity Expansion (XEE) attack. This can lead to disruption of confidentiality, integrity, and availability of protected information. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Python versions 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, consider disabling the XML libraries as a temporary workaround until a patch is available. For libxml2 versions prior to 2.9.1-r1, update to version 2.9.1-r1 or later to resolve the issue. As a general mitigation measure, restrict access to the XML libraries to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09713
CVE-2013-1664
GHSA-QRH7-X6FP-C2MP
RHSA-2013:0596
RHSA-2013:0657
RHSA-2013:0658
RHSA-2013:0670

Produtos afetados

Python
Libxml2