PT-2014-1860 · Xmlsoft+5 · Libxml2+5

Publicado

2014-10-16

·

Atualizado

2024-06-15

·

CVE-2014-3660

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.2 libxml2-devel version 2.9.1 libxml2-debuginfo versions 2.6.26 and 2.9.1 libxml2-python version 2.9.1 libxml2-static version 2.9.1
Description The issue is related to the libxml2 package, which can lead to a denial of service due to CPU consumption. This can be caused by a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack. The vulnerability can be exploited remotely.
Recommendations For libxml2 versions prior to 2.9.2, update to version 2.9.2 or later. For libxml2-devel version 2.9.1, update to a version that includes the fix for this issue. For libxml2-debuginfo versions 2.6.26 and 2.9.1, update to a version that includes the fix for this issue. For libxml2-python version 2.9.1, update to a version that includes the fix for this issue. For libxml2-static version 2.9.1, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the use of entity expansion in libxml2 until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2014-2345
BDU:2015-07045
BDU:2015-07047
BDU:2015-07048
BDU:2015-07049
BDU:2015-07050
BDU:2015-07409
BDU:2015-09191
BDU:2015-09192
BDU:2015-09193
BDU:2015-09194
BDU:2015-09195
BDU:2015-09196
BDU:2015-09789
CESA-2014_1655
CVE-2014-3660
DLA-151-1
DLA-80-1
DSA-2978-2
DSA-3057-1
DSA-3057-2
MGASA-2014-0418
OPENSUSE-SU-2024:10192-1
RHSA-2014:1655
RHSA-2014:1885
RHSA-2014_1655
RHSA-2014_1885
SUSE-SU-2014_1440-1
SUSE-SU-2015_0003-1
USN-2389-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2