Ghidra XML External Entity Injection Vulnerability
BID:107517
Info
Ghidra XML External Entity Injection Vulnerability
| Bugtraq ID: | 107517 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2019 12:00AM |
| Updated: | Mar 18 2019 12:00AM |
| Credit: | sghctoma |
| Vulnerable: |
NSA Ghidra 9.0 |
| Not Vulnerable: | |
Discussion
Ghidra XML External Entity Injection Vulnerability
Ghidra is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or execute arbitrary code in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
Ghidra is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or execute arbitrary code in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
Solution / Fix
Ghidra XML External Entity Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ghidra XML External Entity Injection Vulnerability
References:
References:
- Ghidra From XXE to RCE (tencent.com)
- Project handling is susceptible to XXE #71 (NationalSecurityAgency)
- 5alt/ultrarelay (5alt)
- Ghidra Homepage (NSA)