CVE Vulnerabilities

CVE-2015-3451

Improper Restriction of XML External Entity Reference

Published: May 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Xml-libxml Xml-libxml_project * 2.0118 (including)
Libxml-libxml-perl Ubuntu precise *
Libxml-libxml-perl Ubuntu trusty *
Libxml-libxml-perl Ubuntu upstream *
Libxml-libxml-perl Ubuntu utopic *
Libxml-libxml-perl Ubuntu vivid *

Potential Mitigations

References