perl-xml-libxml: information disclosure
| Package(s): | perl-xml-libxml | CVE #(s): | CVE-2015-3451 | ||||||||||||||||||||||||||||||||||||
| Created: | May 1, 2015 | Updated: | September 8, 2015 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
Unpreserved unset options after a _clone() call (e.g: in load_xml()) leads to not preserved expand_entities. Therefore it leads to a XML-External-Entity Vulnerability. This vulnerability may lead to the disclosure of confidential data, denial of service, port scanning from the perspective of the machine where the parser is located, and other system impacts. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
