CVE-2016-9318
Summary
| CVE | CVE-2016-9318 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-16 00:59:00 UTC |
| Updated | 2022-04-08 23:15:00 UTC |
| Description | libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2972-1] libxml2 security update |
MLIST |
lists.debian.org |
|
| libxml2: Multiple vulnerabilities (GLSA 201711-01) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| USN-3739-1: libxml2 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3739-2: libxml2 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| libxml2 CVE-2016-9318 XML External Entity Injection Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| xmlsec vulnerable to XXE · Issue #43 · lsh123/xmlsec · GitHub |
MISC |
github.com |
Exploit, Patch, Third Party Advisory |
| Bug 772726 – XXE problems continue |
MISC |
bugzilla.gnome.org |
Issue Tracking, Patch, Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179176 Debian Security Update for libxml2 (DLA 2972-1)
- 500347 Alpine Linux Security Update for libxml2
- 504110 Alpine Linux Security Update for libxml2
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 710359 Gentoo Linux libxml2 Multiple Vulnerabilities (GLSA 201711-01)