libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxml2 | Sep 20, 2017 | Nov 16, 2016 |
| Debian | — | Upgrade libxml2 | Apr 11, 2022 | Nov 16, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | Nov 15, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2 | Nov 30, 2017 | Nov 15, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-python | Nov 30, 2017 | Nov 15, 2016 |
| Oracle Solaris | — | Upgrade library/python/libxml2-27 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/python/libxml2-34 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3Upgrade library/libxml2 to version 2.9.5-0.175.3.27.0.1.0 on Solaris 11.3 | Dec 19, 2017 | Nov 15, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 6, 2016 |
| Suse | — | Upgrade libxml2Upgrade libxml2-toolsUpgrade libxml2-pythonUpgrade python-libxml2Upgrade libxml2-2Upgrade libxml2-develUpgrade libxml2-2-32bitUpgrade libxml2-docUpgrade libxml2-x86Upgrade sles12sp2-docker-imageUpgrade libxml2-32bitUpgrade sles12sp1-docker-imageUpgrade libxml2-devel-32bitUpgrade sles12-docker-image | Jan 17, 2017 | Nov 15, 2016 |
| Ubuntu | — | Upgrade libxml2Upgrade python-libxml2Upgrade python3-libxml2Upgrade libxml2-utils | Aug 17, 2018 | Nov 15, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub