SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9318

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct…

MEDIUM 5.5EPSS 2.94%

Does this matter?

Lower severity and a low EPSS score (2.94%). Track it; it rarely justifies an emergency change on its own.

Description

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
2.94% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
xmlsoft/libxml2 · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.