Libxml2 Recursive Entity Evaluation Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020728
|
|
SecurityTracker URL: http://securitytracker.com/id?1020728
|
|
CVE Reference: CVE-2008-3281
(Links to External Site)
|
Date: Aug 21 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: A vulnerability was reported in Libxml2. A remote user can cause denial of service conditions.
A remote user can create a specially crafted XML document that, when processed by the target application using libxml2, will cause
the application to consume excessive memory and CPU resources on the target system.
Andreas Solberg reported this vulnerability.
|
Impact: A remote user can create an XML document that, when processed by the target application, will consume excessive memory and CPU resources on the target system.
|
Solution: The vendor has issued a source code fix, available via SVN.
|
Vendor URL: xmlsoft.org/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 21 Aug 2008 15:45:41 -0400
Subject: libxml
|
https://bugzilla.redhat.com/show_bug.cgi?id=458086
CVE-2008-3281 libxml2 denial of service
|
|