CVE-2013-0338
Summary
| CVE | CVE-2013-0338 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-25 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 10.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 11.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 12.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | - | lts | All |
| Operating System | Opensuse | Opensuse | 12.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 12.2 | All | All | All |
| Operating System | Opensuse | Opensuse | 12.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.7.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.7.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.7.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.7.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.7.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.10 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.13 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.14 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.16 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 1.8.9 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.0.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.1.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.1.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.0 | beta | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.10 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.2.9 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.10 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.12 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.13 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.14 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.3.9 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.10 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.12 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.13 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.14 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.15 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.16 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.17 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.18 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.19 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.20 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.21 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.22 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.23 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.24 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.25 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.26 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.27 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.28 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.29 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.30 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.4.9 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.10 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.12 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.13 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.14 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.16 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.17 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.18 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.20 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.21 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.22 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.23 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.24 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.25 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.26 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.27 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.28 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.29 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.30 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.31 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.32 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.9 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.0 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.1 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.2 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.3 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.4 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.5 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.7.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.9.0 | rc1 | All | All |
| Application | Xmlsoft | Libxml2 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2013:0552-1: moderate: libxml2: fixed two entity expansion p | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| '[security bulletin] HPSBGN03302 rev.1 - HP IceWall Federation Agent, Remote Denial of Service (DoS)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| openSUSE-SU-2013:0555-1: moderate: libxml2: fixed two entity expansion p | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support / Security / Advisories / / MDVSA-2013:056 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Advisory SA52662 - Debian update for libxml2 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| libxml2 - XML parser and markup toolkit | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Oracle Critical Patch Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Bug 912400 – CVE-2013-0338 libxml2: CPU consumption DoS when performing string substitutions during entities expansion | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [security-announce] SUSE-SU-2013:1627-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2652-1 libxml2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-1782-1: libxml2 vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.