CVE-2003-1564

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2003-12-31 05:00

Updated : 2024-02-02 14:10


NVD link : CVE-2003-1564

Mitre link : CVE-2003-1564

CVE.ORG link : CVE-2003-1564


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')