6.5

CVE-2008-3281

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

Data is provided by the National Vulnerability Database (NVD)
XmlsoftLibxml2 Version <= 2.6.32
AppleSafari Version < 4.0
AppleiPhone OS Version >= 1.0.0 < 3.0
FedoraprojectFedora Version9
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04
DebianDebian Linux Version4.0
RedhatEnterprise Linux Eus Version4.7
RedhatEnterprise Linux Eus Version5.2
VMwareEsx Version2.5.4
VMwareEsx Version2.5.5
VMwareEsx Version3.0.2
VMwareEsx Version3.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.8% 0.731
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

http://www.securityfocus.com/archive/1/497962/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.debian.org/security/2008/dsa-1631
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/30783
Patch
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1020728
Third Party Advisory
Broken Link
VDB Entry