PT-2022-11601 · Unknown+1 · Xml-Conduit+1

Jgm

·

Published

2022-12-18

·

Updated

2025-11-14

·

CVE-2021-4249

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions xml-conduit versions prior to 1.9.1.0
Description A vulnerability was found in the DOCTYPE Entity Expansion Handler component of xml-conduit, affecting an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs. The manipulation leads to an infinite loop and can be launched remotely.
Recommendations For versions prior to 1.9.1.0, upgrade to version 1.9.1.0 to address this issue. As a temporary workaround, consider restricting the use of the DOCTYPE Entity Expansion Handler component until the upgrade is applied.

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2021-4249
HSEC-2023-0004

Affected Products

Debian
Xml-Conduit