Description
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1631-1 | New libxml2 packages fix denial of service |
Ubuntu USN |
USN-640-1 | libxml2 vulnerability |
Ubuntu USN |
USN-644-1 | libxml2 vulnerabilities |
References
History
No history.
Subscriptions
Apple
Subscribe
Iphone Os
Subscribe
Safari
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Vmware
Subscribe
Esx
Subscribe
Xmlsoft
Subscribe
Libxml2
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T09:28:41.985Z
Reserved: 2008-07-24T00:00:00.000Z
Link: CVE-2008-3281
No data.
Status : Deferred
Published: 2008-08-27T20:41:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-3281
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN