A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1008-1 | libxml2 security update |
Debian DSA |
DSA-3952-1 | libxml2 security update |
EUVD |
EUVD-2017-16402 | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable). |
Ubuntu USN |
USN-3424-1 | libxml2 vulnerabilities |
Ubuntu USN |
USN-3424-2 | libxml2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:56:36.523Z
Reserved: 2017-03-31T00:00:00
Link: CVE-2017-7375
No data.
Status : Modified
Published: 2018-02-19T19:29:00.703
Modified: 2024-11-21T03:31:45.350
Link: CVE-2017-7375
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN