PT-2016-3270 · Xmlsoft+5 · Libxml2+5

Kostya Serebryany

·

Publicado

2016-03-12

·

Atualizado

2018-01-18

·

CVE-2016-4449

CVSS v2.0

7.8

Alta

VetorAV:A/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.4
Description The issue allows context-dependent attackers to read arbitrary files or cause a denial of service due to an XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function. This vulnerability can be exploited by remote attackers to disclose protected information or cause resource consumption.
Recommendations For libxml2 versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider enabling validating mode to minimize the risk of exploitation. Restrict access to sensitive files and resources to prevent unauthorized disclosure of information.

Correção

DoS

XXE

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1221
ALT-PU-2017-1240
BDU:2018-01272
CESA-2016_1292
CVE-2016-4449
DLA-503-1
DSA-3593-1
MGASA-2016-0263
OPENSUSE-SU-2016_1595-1
RHSA-2016:1292
RHSA-2016_1292
SUSE-SU-2016:1538-1
SUSE-SU-2016:1604-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2994-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2