A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libxml2 | Aug 23, 2017 | Jul 1, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-libxml2 | Nov 13, 2017 | Nov 10, 2017 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-libxml2huawei-euleros-2_0_sp1-upgrade-libxml2-develhuawei-euleros-2_0_sp1-upgrade-libxml2-python | Apr 3, 2018 | Feb 19, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libxml2huawei-euleros-2_0_sp2-upgrade-libxml2-develhuawei-euleros-2_0_sp2-upgrade-libxml2-python | May 2, 2018 | Feb 19, 2018 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Feb 19, 2018 |
| Suse | — | suse-upgrade-libxml2suse-upgrade-libxml2-2suse-upgrade-libxml2-2-32bitsuse-upgrade-libxml2-32bitsuse-upgrade-libxml2-develsuse-upgrade-libxml2-devel-32bitsuse-upgrade-libxml2-docsuse-upgrade-libxml2-pythonsuse-upgrade-libxml2-toolssuse-upgrade-libxml2-x86suse-upgrade-python-libxml2suse-upgrade-sles12sp2-docker-image | Jul 1, 2017 | Jul 1, 2017 |
| Ubuntu | ubuntu-upgrade-libxml2 | Sep 19, 2017 | Jul 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub