CVE-2017-9233

Related Vulnerabilities: CVE-2017-9233  

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

The MITRE CVE dictionary describes this issue as:

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

Find out more about CVE-2017-9233 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat JBoss EWS 2 httpd Will not fix
Red Hat JBoss EAP 6 httpd Will not fix
Red Hat Enterprise Linux 7 xulrunner Will not fix
Red Hat Enterprise Linux 7 firefox Will not fix
Red Hat Enterprise Linux 7 expat Will not fix
Red Hat Enterprise Linux 7 thunderbird Will not fix
Red Hat Enterprise Linux 6 firefox Will not fix
Red Hat Enterprise Linux 6 thunderbird Will not fix
Red Hat Enterprise Linux 6 xulrunner Will not fix
Red Hat Enterprise Linux 6 compat-expat1 Will not fix
Red Hat Enterprise Linux 5 thunderbird Will not fix
Red Hat Enterprise Linux 5 expat Will not fix
Red Hat Enterprise Linux 5 xmlrpc-c Will not fix
Red Hat Enterprise Linux 5 firefox Will not fix
Red Hat Enterprise Linux 5 xulrunner Will not fix
RHEV Manager 3 mingw-virt-viewer Will not fix

Mitigation

Do not parse untrusted arbitrary XML data using the expat package.

External References