[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3243-1 libxml-libxml-perl -- libxml-libxml-perl

ID: oval:org.secpod.oval:def:602075Date: (C)2015-05-11   (M)2022-09-22
Class: PATCHFamily: unix




Tilmann Haak from xing.com discovered that XML::LibXML, a Perl interface to the libxml2 library, did not respect the expand_entities parameter to disable processing of external entities in some circumstances. This may allow attackers to gain read access to otherwise protected ressources, depending on how the library is used.

Platform:
Debian 8.x
Debian 7.x
Product:
libxml-libxml-perl
Reference:
DSA-3243-1
CVE-2015-3451
CVE    1
CVE-2015-3451
CPE    5
cpe:/a:xmlsoft:libxml-libxml-perl
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:7.0
...

© SecPod Technologies