PT-2013-1218 · Gentoo Linux+5 · Libxml2+5

Jan Lieskovsky

·

Published

2012-11-28

·

Updated

2024-06-15

·

CVE-2013-0338

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.9.0 and earlier
Description The issue affects the libxml2 package in Gentoo Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. It can be exploited remotely. Specifically, the problem allows context-dependent attackers to cause a denial of service by consuming CPU and memory resources via a specially crafted XML file. This XML file would contain an entity declaration with long replacement text and many references to this entity, a scenario described as "internal entity expansion" with linear complexity.
Recommendations For libxml2 versions 2.9.0 and earlier, update to version 2.9.1-r1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external XML files to minimize the risk of exploitation. Avoid using the libxml2 package for parsing untrusted XML files until the issue is resolved.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2345
BDU:2015-09713
CESA-2013_0581
CVE-2013-0338
DSA-2652-1
OPENSUSE-SU-2024:10192-1
RHSA-2013:0581
RHSA-2013_0581
SUSE-SU-2013_0743-1
SUSE-SU-2013_0744-1

Affected Products

Alt Linux
Centos
Junos
Red Hat
Suse
Libxml2