4.3
CVSSv2

CVE-2013-0338

Published: 25/04/2013 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libxml2 2.9.0 and previous versions allows context-dependent malicious users to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2 1.7.0

xmlsoft libxml2 1.7.1

xmlsoft libxml2 2.5.10

xmlsoft libxml2 2.4.23

xmlsoft libxml2 2.4.28

xmlsoft libxml2 2.4.29

xmlsoft libxml2 2.4.22

xmlsoft libxml2 2.6.17

xmlsoft libxml2 2.4.9

xmlsoft libxml2 2.4.8

xmlsoft libxml2 2.4.12

xmlsoft libxml2 2.4.15

xmlsoft libxml2 2.4.14

xmlsoft libxml2 2.2.0

xmlsoft libxml2 1.7.2

xmlsoft libxml2 2.6.11

xmlsoft libxml2 2.4.19

xmlsoft libxml2 2.6.14

xmlsoft libxml2 2.4.26

xmlsoft libxml2 2.4.27

xmlsoft libxml2 2.6.22

xmlsoft libxml2 2.4.21

xmlsoft libxml2 2.6.16

xmlsoft libxml2 2.4.11

xmlsoft libxml2 2.6.24

xmlsoft libxml2 1.8.16

xmlsoft libxml2 2.4.1

xmlsoft libxml2 1.8.13

xmlsoft libxml2 2.3.9

xmlsoft libxml2 2.3.13

xmlsoft libxml2 2.3.14

xmlsoft libxml2 2.3.5

xmlsoft libxml2 2.2.8

xmlsoft libxml2 2.2.9

xmlsoft libxml2 1.8.10

xmlsoft libxml2 2.2.2

xmlsoft libxml2 1.8.4

xmlsoft libxml2 2.7.8

xmlsoft libxml2 2.6.32

xmlsoft libxml2 2.6.8

xmlsoft libxml2 2.6.26

xmlsoft libxml2 2.7.6

xmlsoft libxml2 2.6.31

xmlsoft libxml2

xmlsoft libxml2 2.4.6

xmlsoft libxml2 2.4.7

xmlsoft libxml2 2.3.12

xmlsoft libxml2 1.8.14

xmlsoft libxml2 2.3.7

xmlsoft libxml2 2.3.6

xmlsoft libxml2 2.2.11

xmlsoft libxml2 2.2.10

xmlsoft libxml2 2.2.4

xmlsoft libxml2 2.2.1

xmlsoft libxml2 1.8.6

xmlsoft libxml2 1.8.7

xmlsoft libxml2 2.6.9

xmlsoft libxml2 2.6.7

xmlsoft libxml2 2.7.4

xmlsoft libxml2 2.7.7

xmlsoft libxml2 2.7.1

xmlsoft libxml2 2.7.0

xmlsoft libxml2 1.7.3

xmlsoft libxml2 1.7.4

xmlsoft libxml2 1.8.0

xmlsoft libxml2 2.6.1

xmlsoft libxml2 2.6.0

xmlsoft libxml2 2.6.2

xmlsoft libxml2 2.6.12

xmlsoft libxml2 2.4.17

xmlsoft libxml2 2.4.16

xmlsoft libxml2 2.4.25

xmlsoft libxml2 2.6.20

xmlsoft libxml2 2.4.10

xmlsoft libxml2 2.6.23

xmlsoft libxml2 2.4.2

xmlsoft libxml2 2.4.3

xmlsoft libxml2 2.3.10

xmlsoft libxml2 2.5.7

xmlsoft libxml2 2.3.4

xmlsoft libxml2 2.3.3

xmlsoft libxml2 2.2.7

xmlsoft libxml2 2.2.6

xmlsoft libxml2 2.1.1

xmlsoft libxml2 1.8.5

xmlsoft libxml2 1.8.2

xmlsoft libxml2 2.6.5

xmlsoft libxml2 2.6.6

xmlsoft libxml2 2.9.0

xmlsoft libxml2 2.6.27

xmlsoft libxml2 2.6.29

xmlsoft libxml2 2.6.28

xmlsoft libxml2 2.7.3

xmlsoft libxml2 1.8.1

xmlsoft libxml2 2.5.0

xmlsoft libxml2 2.5.4

xmlsoft libxml2 2.5.11

xmlsoft libxml2 2.6.13

xmlsoft libxml2 2.4.30

xmlsoft libxml2 2.4.20

xmlsoft libxml2 2.4.18

xmlsoft libxml2 2.4.24

xmlsoft libxml2 2.6.18

xmlsoft libxml2 2.4.13

xmlsoft libxml2 2.6.21

xmlsoft libxml2 2.4.4

xmlsoft libxml2 2.4.5

xmlsoft libxml2 2.3.11

xmlsoft libxml2 2.5.8

xmlsoft libxml2 2.3.2

xmlsoft libxml2 2.3.1

xmlsoft libxml2 2.3.8

xmlsoft libxml2 2.2.5

xmlsoft libxml2 2.3.0

xmlsoft libxml2 1.8.9

xmlsoft libxml2 2.2.3

xmlsoft libxml2 1.8.3

xmlsoft libxml2 2.0.0

xmlsoft libxml2 2.1.0

xmlsoft libxml2 2.6.3

xmlsoft libxml2 2.6.4

xmlsoft libxml2 2.6.30

xmlsoft libxml2 2.7.5

xmlsoft libxml2 2.6.25

xmlsoft libxml2 2.7.2

canonical ubuntu linux 8.04

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

canonical ubuntu linux 11.10

canonical ubuntu linux 10.04

opensuse opensuse 12.3

opensuse opensuse 12.2

opensuse opensuse 12.1

Vendor Advisories

Synopsis Moderate: libxml2 security update Type/Severity Security Advisory: Moderate Topic Updated libxml2 packages that fix one security issue are now available forRed Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerabi ...
Debian Bug report logs - #702260 libxml2: CVE-2013-0338 CVE-2013-0339 Package: libxml2; Maintainer for libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Source for libxml2 is src:libxml2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 4 Mar 2013 15:42: ...
libxml2 could be made to hang if it received specially crafted input ...
Brad Hill of iSEC Partners discovered that many XML implementations are vulnerable to external entity expansion issues, which can be used for various purposes such as firewall circumvention, disguising an IP address, and denial-of-service libxml2 was susceptible to these problems when performing string substitution during entity expansion For the ...
libxml2 290 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity ...