CVE-2017-9233
גבוהה 7.5
תיאור (מקור, אנגלית)
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-611, CWE-835
מוצרים מושפעים
libexpat_project: libexpat; python: python; debian: debian linux
קישורים
- https://libexpat.github.io/doc/cve-2017-9233/ ExploitTechnical DescriptionVendor Advisory
- https://libexpat.github.io/doc/cve-2017-9233/ ExploitTechnical DescriptionVendor Advisory
- http://www.debian.org/security/2017/dsa-3898 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/06/17/7 Mailing ListVDB Entry
- http://www.securityfocus.com/bid/99276 Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039427 Third Party AdvisoryVDB Entry
- https://github.com/libexpat/libexpat/blob/master/expat/Changes Release NotesThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600…
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61c…
- https://support.apple.com/HT208112 Third Party Advisory