The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2-pythonUpgrade libxml2-debuginfoUpgrade libxml2Upgrade libxml2-staticUpgrade libxml2-devel | Apr 27, 2020 | Aug 14, 2015 |
| Apple Osx Libxml2 | — | Apply OS X security update 2016-002Upgrade macOS to the latest version | Mar 29, 2016 | Aug 14, 2015 |
| Debian | — | Upgrade libxml2 | Jan 4, 2016 | Aug 14, 2015 |
| Freebsd | — | Upgrade libxml2Upgrade linux-f10-libxml2Upgrade linux-c6-libxml2 | Dec 10, 2025 | Jul 1, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Aug 14, 2015 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | Aug 14, 2015 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-develUpgrade libxml2-static | Oct 16, 2024 | Aug 14, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 14, 2015 |
| Suse | — | Upgrade libxml2Upgrade libxml2-develUpgrade sles12-docker-imageUpgrade python-libxml2Upgrade libxml2-x86Upgrade libxml2-32bitUpgrade python3-libxml2-pythonUpgrade libxml2-devel-32bitUpgrade ruby2.5-rubygem-nokogiriUpgrade libxml2-pythonUpgrade libxml2-toolsUpgrade libxml2-2Upgrade libxml2-docUpgrade libxml2-2-32bit | Jan 4, 2016 | Aug 14, 2015 |
| Ubuntu | — | Upgrade libxml2 | Nov 23, 2015 | Aug 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub