PT-2015-6235 · Libxml2+3 · Xml-Libxml+3
Tilmann Haak
·
Publicado
2015-05-01
·
Atualizado
2024-06-15
·
CVE-2015-3451
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XML::LibXML versions prior to 2.0119
Description
The issue allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the
new or load xml function. This is due to the clone function not properly setting the expand entities option.Recommendations
For XML::LibXML versions prior to 2.0119, update to version 2.0119 or later to resolve the issue. As a temporary workaround, consider disabling the
clone function or restricting the use of the new and load xml functions until a patch is available. Avoid using these functions with untrusted XML data to minimize the risk of exploitation.Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Xml-Libxml