A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml2 | Aug 23, 2017 | Jul 1, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 13, 2017 | Nov 10, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Apr 3, 2018 | Feb 19, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxml2Upgrade libxml2-pythonUpgrade libxml2-devel | May 2, 2018 | Feb 19, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2018 |
| Suse | — | Upgrade python-libxml2Upgrade libxml2-32bitUpgrade sles12sp2-docker-imageUpgrade libxml2Upgrade libxml2-2Upgrade libxml2-pythonUpgrade libxml2-toolsUpgrade libxml2-x86Upgrade libxml2-docUpgrade libxml2-devel-32bitUpgrade libxml2-develUpgrade libxml2-2-32bit | Jul 1, 2017 | Jul 1, 2017 |
| Ubuntu | — | Upgrade libxml2 | Sep 19, 2017 | Jul 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub