libxml2, possibly before 2.5.0, does not properly detect recursion during...
Vulnerability Description
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-1564
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/31868
- http://xmlsoft.org/news.html
- http://www.stylusstudio.com/xmldev/200302/post20020.html
- http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2
- http://mail.gnome.org/archives/xml/2008-August/msg00034.html
- http://www.redhat.com/support/errata/RHSA-2008-0886.html
More from xmlsoft
View All →Affected Vendor
xmlsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.