PT-2016-3268 · Xmlsoft+5 · Libxml2+5
Simon Lees
·
Publicado
2016-03-12
·
Atualizado
2024-06-15
·
CVE-2016-3705
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 version 2.9.3
Description
The issue is related to the
xmlParserEntityCheck and xmlParseAttValueComplex functions in the parser.c file of the libxml2 library. These functions do not properly track the recursion depth, allowing context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.Recommendations
For libxml2 version 2.9.3, consider updating to a newer version that addresses this issue, as the current version does not properly handle recursion depth in the
xmlParserEntityCheck and xmlParseAttValueComplex functions. As a temporary workaround, consider restricting the use of these functions or limiting the complexity of XML documents to minimize the risk of exploitation.Correção
DoS
RCE
Uncontrolled Recursion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2