|
|
Log in / Subscribe / Register

perl-xml-libxml: information disclosure

Package(s):perl-xml-libxml CVE #(s):CVE-2015-3451
Created:May 1, 2015 Updated:September 8, 2015
Description: From the Arch Linux advisory:

Unpreserved unset options after a _clone() call (e.g: in load_xml()) leads to not preserved expand_entities. Therefore it leads to a XML-External-Entity Vulnerability.

This vulnerability may lead to the disclosure of confidential data, denial of service, port scanning from the perspective of the machine where the parser is located, and other system impacts.

Alerts:
openSUSE openSUSE-SU-2015:1506-1 perl-XML-LibXML 2015-09-07
Fedora FEDORA-2015-7258 perl-XML-LibXML 2015-05-11
Fedora FEDORA-2015-7115 perl-XML-LibXML 2015-05-10
Mandriva MDVSA-2015:231 perl-XML-LibXML 2015-05-07
Mageia MGASA-2015-0199 perl-XML-LibXML 2015-05-06
Ubuntu USN-2592-1 libxml-libxml-perl 2015-05-04
Debian DSA-3243-1 libxml-libxml-perl 2015-05-01
Debian-LTS DLA-214-1 libxml-libxml-perl 2015-04-30
Arch Linux ASA-201504-32 perl-xml-libxml 2015-04-30

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds