Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nios | Infoblox | 8.4.0 (including) | 8.4.8 (including) |
Nios | Infoblox | 8.5.0 (including) | 8.5.0 (including) |
Nios | Infoblox | 8.5.1 (including) | 8.5.1 (including) |