libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Safari | — | Upgrade to Apple Safari version 4.0Uninstall Apple Safari on Windows | Jan 5, 2012 | Aug 27, 2008 |
| Centos_linux | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-python | Dec 1, 2016 | Aug 27, 2008 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Aug 27, 2008 |
| Freebsd | — | Upgrade libxml2 | Dec 10, 2025 | Oct 15, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Aug 27, 2008 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Oct 16, 2024 | Aug 27, 2008 |
| Suse | — | Upgrade libxml2-x86Upgrade libxml2-docUpgrade libxml2-64bitUpgrade libxml2-32bitUpgrade suse-releaseUpgrade libxml2-develUpgrade libxml2-devel-32bitUpgrade libxml2Upgrade libxml2-devel-64bit | Feb 17, 2015 | Aug 27, 2008 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Aug 27, 2008 |
| Vmsa 2008 0017 | — | Apply ESX350-200811405-SG. | Nov 19, 2010 | Aug 27, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub