VulnerabilityModified
CVE-2008-3281
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
MEDIUM 6.5EPSS 2.51%
Does this matter?
Lower severity and a low EPSS score (2.51%). Track it; it rarely justifies an emergency change on its own.
Description
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.51% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-776
- Affected
- xmlsoft/libxml2 · apple/safari · apple/iphone os · fedoraproject/fedora · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · vmware/esx
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlMailing List
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List
- http://lists.vmware.com/pipermail/security-announce/2008/000039.htmlBroken Link
- http://mail.gnome.org/archives/xml/2008-August/msg00034.htmlMailing List, Patch
- http://secunia.com/advisories/31558Broken Link
- http://secunia.com/advisories/31566Broken Link
- http://secunia.com/advisories/31590Broken Link
- http://secunia.com/advisories/31728Broken Link
- http://secunia.com/advisories/31748Broken Link
- http://secunia.com/advisories/31855Broken Link
- http://secunia.com/advisories/31982Broken Link
- http://secunia.com/advisories/32488Broken Link
- http://secunia.com/advisories/32807Broken Link
- http://secunia.com/advisories/32974Broken Link
- http://secunia.com/advisories/35379Broken Link
- http://security.gentoo.org/glsa/glsa-200812-06.xmlThird Party Advisory
- http://support.apple.com/kb/HT3613Third Party Advisory
- http://support.apple.com/kb/HT3639Third Party Advisory
- http://svn.gnome.org/viewvc/libxml2?view=revision&revision=3772Broken Link
- http://wiki.rpath.com/Advisories:rPSA-2008-0325Broken Link
- http://www.debian.org/security/2008/dsa-1631Mailing List, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:180Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:192Broken Link
- http://www.securityfocus.com/archive/1/497962/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30783Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020728Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-640-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2008-0017.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2419Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.