libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
No history.
Information
Published : 2008-08-27 20:41
Updated : 2024-02-02 15:02
NVD link : CVE-2008-3281
Mitre link : CVE-2008-3281
CVE.ORG link : CVE-2008-3281
JSON object : View
Products Affected
vmware
- esx
redhat
- enterprise_linux_server
- enterprise_linux_desktop
- enterprise_linux_eus
- enterprise_linux_workstation
xmlsoft
- libxml2
canonical
- ubuntu_linux
fedoraproject
- fedora
apple
- safari
- iphone_os
debian
- debian_linux
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')