[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2652-1 libxml2 -- external entity expansion

ID: oval:org.secpod.oval:def:600998Date: (C)2013-03-27   (M)2023-12-07
Class: PATCHFamily: unix




Brad Hill of iSEC Partners discovered that many XML implementations are vulnerable to external entity expansion issues, which can be used for various purposes such as firewall circumvention, disguising an IP address, and denial-of-service. libxml2 was susceptible to these problems when performing string substitution during entity expansion.

Platform:
Debian 6.0
Product:
libxml2
Reference:
DSA-2652-1
CVE-2013-0338
CVE-2013-0339
CVE    2
CVE-2013-0338
CVE-2013-0339
CPE    129
cpe:/a:xmlsoft:libxml2
cpe:/a:xmlsoft:libxml2:2.3.9
cpe:/a:xmlsoft:libxml2:2.7.5
cpe:/a:xmlsoft:libxml2:2.3.8
...

© SecPod Technologies