LWN.net Logo

libxml2: denial of service

Package(s):libxml2 CVE #(s):CVE-2013-0339
Created:March 26, 2013 Updated:March 27, 2013
Description: From the Debian advisory:

Brad Hill of iSEC Partners discovered that many XML implementations are vulnerable to external entity expansion issues, which can be used for various purposes such as firewall circumvention, disguising an IP address, and denial-of-service. libxml2 was susceptible to these problems when performing string substitution during entity expansion.

Alerts:
Debian DSA-2652-1 2013-03-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds