CVE-2003-1564

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://mail.gnome.org/archives/xml/2008-August/msg00034.html - Mailing List, Patch () http://mail.gnome.org/archives/xml/2008-August/msg00034.html - Mailing List, Patch
References () http://secunia.com/advisories/31868 - Broken Link () http://secunia.com/advisories/31868 - Broken Link
References () http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2 - Issue Tracking () http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2 - Issue Tracking
References () http://www.redhat.com/support/errata/RHSA-2008-0886.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2008-0886.html - Broken Link
References () http://www.stylusstudio.com/xmldev/200302/post20020.html - Broken Link () http://www.stylusstudio.com/xmldev/200302/post20020.html - Broken Link
References () http://xmlsoft.org/news.html - Release Notes () http://xmlsoft.org/news.html - Release Notes

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:47


NVD link : CVE-2003-1564

Mitre link : CVE-2003-1564

CVE.ORG link : CVE-2003-1564


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')