libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
References
Link | Resource |
---|---|
http://mail.gnome.org/archives/xml/2008-August/msg00034.html | Mailing List Patch |
http://secunia.com/advisories/31868 | Broken Link |
http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2 | Issue Tracking |
http://www.redhat.com/support/errata/RHSA-2008-0886.html | Broken Link |
http://www.stylusstudio.com/xmldev/200302/post20020.html | Broken Link |
http://xmlsoft.org/news.html | Release Notes |
http://mail.gnome.org/archives/xml/2008-August/msg00034.html | Mailing List Patch |
http://secunia.com/advisories/31868 | Broken Link |
http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2 | Issue Tracking |
http://www.redhat.com/support/errata/RHSA-2008-0886.html | Broken Link |
http://www.stylusstudio.com/xmldev/200302/post20020.html | Broken Link |
http://xmlsoft.org/news.html | Release Notes |
Configurations
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://mail.gnome.org/archives/xml/2008-August/msg00034.html - Mailing List, Patch | |
References | () http://secunia.com/advisories/31868 - Broken Link | |
References | () http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2 - Issue Tracking | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0886.html - Broken Link | |
References | () http://www.stylusstudio.com/xmldev/200302/post20020.html - Broken Link | |
References | () http://xmlsoft.org/news.html - Release Notes |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:47
NVD link : CVE-2003-1564
Mitre link : CVE-2003-1564
CVE.ORG link : CVE-2003-1564
JSON object : View
Products Affected
xmlsoft
- libxml2
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')