PT-2016-3270 · Xmlsoft+5 · Libxml2+5
Kostya Serebryany
·
Published
2016-03-12
·
Updated
2018-01-18
·
CVE-2016-4449
CVSS v2.0
7.8
High
| Vector | AV:A/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 versions prior to 2.9.4
Description
The issue allows context-dependent attackers to read arbitrary files or cause a denial of service due to an XML external entity (XXE) vulnerability in the
xmlStringLenDecodeEntities function. This vulnerability can be exploited by remote attackers to disclose protected information or cause resource consumption.Recommendations
For libxml2 versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider enabling validating mode to minimize the risk of exploitation. Restrict access to sensitive files and resources to prevent unauthorized disclosure of information.
Fix
DoS
XXE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2