XML External Entity (XXE) Injection
Affecting libxml2 package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2016-9318
- CWE
- CWE-611
- Snyk ID
- SNYK-DEBIAN9-LIBXML2-429495
- Disclosed
- 16 Nov, 2016
- Published
- 16 Nov, 2016