5
CVE-2015-3451
- EPSS 4.01%
- Veröffentlicht 12.05.2015 19:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xml-libxml Project ≫ Xml-libxml SwPlatform perl Version <= 2.0118
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Fedoraproject ≫ Fedora Version 20
Fedoraproject ≫ Fedora Version 21
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.01% | 0.892 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
http://advisories.mageia.org/MGASA-2015-0199.html
http://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changes
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.html
http://lists.opensuse.org/opensuse-updates/2015-09/msg00006.html
http://www.debian.org/security/2015/dsa-3243
http://www.mandriva.com/security/advisories?name=MDVSA-2015:231
http://www.openwall.com/lists/oss-security/2015/04/25/2
http://www.openwall.com/lists/oss-security/2015/04/30/1
http://www.securityfocus.com/bid/74333
http://www.ubuntu.com/usn/USN-2592-1
https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/