CVE-2014-0191
Summary
| CVE | CVE-2014-0191 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-21 14:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Fusion Middleware | 11.1.1.7.0 | All | All | All |
| Application | Oracle | Fusion Middleware | 12.1.2.0.0 | All | All | All |
| Application | Oracle | Fusion Middleware | 12.1.3.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases | af854a3a-2127-422b-91ae-364da2661108 | xmlsoft.org | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Oracle Critical Patch Update - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| 1090976 – (CVE-2014-0191) CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| libxml2 - XML parser and markup toolkit | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | |
| IBM Security Bulletin: Rational Systems Tester is affected by Libxml2 vulnerability (CVE-2014-0191) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| About the security content of iOS 8.4.1 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2015-08-13-3 iOS 8.4.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Oracle Critical Patch Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Vendor Advisory |
| openSUSE-SU-2015:2372-1: moderate: Security update for libxml2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.