CVE-2017-7375 - CVE House
Back to Database
Status published Unknown CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with...

Vulnerability Description

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7375

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libxml2, debian linux, android
Vulnerable Versions:
0, 2.9.4, 7.0, 8.0, 9.0, 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.1.1, 7.1.2

Timeline

Official Publish: February 19th, 2018
Last Modified: December 3rd, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.