Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0339


libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.


Published

2014-01-21T18:55:09.053

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xmlsoft libxml2 ≤ 2.9.1 Yes
Application xmlsoft libxml2 1.7.0 Yes
Application xmlsoft libxml2 1.7.1 Yes
Application xmlsoft libxml2 1.7.2 Yes
Application xmlsoft libxml2 1.7.3 Yes
Application xmlsoft libxml2 1.7.4 Yes
Application xmlsoft libxml2 1.8.0 Yes
Application xmlsoft libxml2 1.8.1 Yes
Application xmlsoft libxml2 1.8.2 Yes
Application xmlsoft libxml2 1.8.3 Yes
Application xmlsoft libxml2 1.8.4 Yes
Application xmlsoft libxml2 1.8.5 Yes
Application xmlsoft libxml2 1.8.6 Yes
Application xmlsoft libxml2 1.8.7 Yes
Application xmlsoft libxml2 1.8.9 Yes
Application xmlsoft libxml2 1.8.10 Yes
Application xmlsoft libxml2 1.8.13 Yes
Application xmlsoft libxml2 1.8.14 Yes
Application xmlsoft libxml2 1.8.16 Yes
Application xmlsoft libxml2 2.0.0 Yes
Application xmlsoft libxml2 2.1.0 Yes
Application xmlsoft libxml2 2.1.1 Yes
Application xmlsoft libxml2 2.2.0 Yes
Application xmlsoft libxml2 2.2.0 Yes
Application xmlsoft libxml2 2.2.1 Yes
Application xmlsoft libxml2 2.2.2 Yes
Application xmlsoft libxml2 2.2.3 Yes
Application xmlsoft libxml2 2.2.4 Yes
Application xmlsoft libxml2 2.2.5 Yes
Application xmlsoft libxml2 2.2.6 Yes
Application xmlsoft libxml2 2.2.7 Yes
Application xmlsoft libxml2 2.2.8 Yes
Application xmlsoft libxml2 2.2.9 Yes
Application xmlsoft libxml2 2.2.10 Yes
Application xmlsoft libxml2 2.2.11 Yes
Application xmlsoft libxml2 2.3.0 Yes
Application xmlsoft libxml2 2.3.1 Yes
Application xmlsoft libxml2 2.3.2 Yes
Application xmlsoft libxml2 2.3.3 Yes
Application xmlsoft libxml2 2.3.4 Yes
Application xmlsoft libxml2 2.3.5 Yes
Application xmlsoft libxml2 2.3.6 Yes
Application xmlsoft libxml2 2.3.7 Yes
Application xmlsoft libxml2 2.3.8 Yes
Application xmlsoft libxml2 2.3.9 Yes
Application xmlsoft libxml2 2.3.10 Yes
Application xmlsoft libxml2 2.3.11 Yes
Application xmlsoft libxml2 2.3.12 Yes
Application xmlsoft libxml2 2.3.13 Yes
Application xmlsoft libxml2 2.3.14 Yes
Application xmlsoft libxml2 2.4.1 Yes
Application xmlsoft libxml2 2.4.2 Yes
Application xmlsoft libxml2 2.4.3 Yes
Application xmlsoft libxml2 2.4.4 Yes
Application xmlsoft libxml2 2.4.5 Yes
Application xmlsoft libxml2 2.4.6 Yes
Application xmlsoft libxml2 2.4.7 Yes
Application xmlsoft libxml2 2.4.8 Yes
Application xmlsoft libxml2 2.4.9 Yes
Application xmlsoft libxml2 2.4.10 Yes
Application xmlsoft libxml2 2.4.11 Yes
Application xmlsoft libxml2 2.4.12 Yes
Application xmlsoft libxml2 2.4.13 Yes
Application xmlsoft libxml2 2.4.14 Yes
Application xmlsoft libxml2 2.4.15 Yes
Application xmlsoft libxml2 2.4.16 Yes
Application xmlsoft libxml2 2.4.17 Yes
Application xmlsoft libxml2 2.4.18 Yes
Application xmlsoft libxml2 2.4.19 Yes
Application xmlsoft libxml2 2.4.20 Yes
Application xmlsoft libxml2 2.4.21 Yes
Application xmlsoft libxml2 2.4.22 Yes
Application xmlsoft libxml2 2.4.23 Yes
Application xmlsoft libxml2 2.4.24 Yes
Application xmlsoft libxml2 2.4.25 Yes
Application xmlsoft libxml2 2.4.26 Yes
Application xmlsoft libxml2 2.4.27 Yes
Application xmlsoft libxml2 2.4.28 Yes
Application xmlsoft libxml2 2.4.29 Yes
Application xmlsoft libxml2 2.4.30 Yes
Application xmlsoft libxml2 2.5.0 Yes
Application xmlsoft libxml2 2.5.4 Yes
Application xmlsoft libxml2 2.5.7 Yes
Application xmlsoft libxml2 2.5.8 Yes
Application xmlsoft libxml2 2.5.10 Yes
Application xmlsoft libxml2 2.5.11 Yes
Application xmlsoft libxml2 2.6.0 Yes
Application xmlsoft libxml2 2.6.1 Yes
Application xmlsoft libxml2 2.6.2 Yes
Application xmlsoft libxml2 2.6.3 Yes
Application xmlsoft libxml2 2.6.4 Yes
Application xmlsoft libxml2 2.6.5 Yes
Application xmlsoft libxml2 2.6.6 Yes
Application xmlsoft libxml2 2.6.7 Yes
Application xmlsoft libxml2 2.6.8 Yes
Application xmlsoft libxml2 2.6.9 Yes
Application xmlsoft libxml2 2.6.11 Yes
Application xmlsoft libxml2 2.6.12 Yes
Application xmlsoft libxml2 2.6.13 Yes
Application xmlsoft libxml2 2.6.14 Yes
Application xmlsoft libxml2 2.6.16 Yes
Application xmlsoft libxml2 2.6.17 Yes
Application xmlsoft libxml2 2.6.18 Yes
Application xmlsoft libxml2 2.6.20 Yes
Application xmlsoft libxml2 2.6.21 Yes
Application xmlsoft libxml2 2.6.22 Yes
Application xmlsoft libxml2 2.6.23 Yes
Application xmlsoft libxml2 2.6.24 Yes
Application xmlsoft libxml2 2.6.25 Yes
Application xmlsoft libxml2 2.6.26 Yes
Application xmlsoft libxml2 2.6.27 Yes
Application xmlsoft libxml2 2.6.28 Yes
Application xmlsoft libxml2 2.6.29 Yes
Application xmlsoft libxml2 2.6.30 Yes
Application xmlsoft libxml2 2.6.31 Yes
Application xmlsoft libxml2 2.6.32 Yes
Application xmlsoft libxml2 2.7.0 Yes
Application xmlsoft libxml2 2.7.1 Yes
Application xmlsoft libxml2 2.7.2 Yes
Application xmlsoft libxml2 2.7.3 Yes
Application xmlsoft libxml2 2.7.4 Yes
Application xmlsoft libxml2 2.7.5 Yes
Application xmlsoft libxml2 2.7.6 Yes
Application xmlsoft libxml2 2.7.7 Yes
Application xmlsoft libxml2 2.7.8 Yes
Application xmlsoft libxml2 2.8.0 Yes
Application xmlsoft libxml2 2.9.0 Yes
Application xmlsoft libxml2 2.9.0 Yes
Operating System canonical ubuntu_linux 10.04 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 12.10 Yes
Operating System canonical ubuntu_linux 13.04 Yes
Operating System debian debian_linux 6.0 Yes
Operating System debian debian_linux 7.0 Yes
Operating System suse linux_enterprise_server 10 Yes

References