PT-2015-6235 · Libxml2+3 · Xml-Libxml+3

Tilmann Haak

·

Published

2015-05-01

·

Updated

2024-06-15

·

CVE-2015-3451

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions XML::LibXML versions prior to 2.0119
Description The issue allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the new or load xml function. This is due to the clone function not properly setting the expand entities option.
Recommendations For XML::LibXML versions prior to 2.0119, update to version 2.0119 or later to resolve the issue. As a temporary workaround, consider disabling the clone function or restricting the use of the new and load xml functions until a patch is available. Avoid using these functions with untrusted XML data to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1880
CVE-2015-3451
DLA-214-1
DSA-3243-1
MGASA-2015-0199
OPENSUSE-SU-2024:10516-1
SUSE-SU-2015:1439-1
SUSE-SU-2015_1439-1
USN-2592-1

Affected Products

Alt Linux
Suse
Ubuntu
Xml-Libxml