Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
BID:67233
Info
Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
| Bugtraq ID: | 67233 |
| Class: | Unknown |
| CVE: |
CVE-2014-0191 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2014 12:00AM |
| Updated: | Jul 05 2016 09:32PM |
| Credit: | Daniel Berrange |
| Vulnerable: |
XMLSoft Libxml2 2.7.8 XMLSoft Libxml2 2.7.7 XMLSoft Libxml2 2.7.6 XMLSoft Libxml2 2.7.5 XMLSoft Libxml2 2.7.4 XMLSoft Libxml2 2.7.3 XMLSoft Libxml2 2.7.2 XMLSoft Libxml2 2.7.1 XMLSoft Libxml2 2.7 XMLSoft Libxml2 2.6.32 XMLSoft Libxml2 2.6.31 XMLSoft Libxml2 2.6.30 XMLSoft Libxml2 2.6.26 XMLSoft Libxml2 2.6.22 XMLSoft Libxml2 2.6.20 XMLSoft Libxml2 2.6.18 XMLSoft Libxml2 2.6.17 XMLSoft Libxml2 2.6.16 XMLSoft Libxml2 2.6.15 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6 .0 XMLSoft Libxml2 2.5.11 XMLSoft Libxml2 2.5.10 XMLSoft Libxml2 2.5.8 XMLSoft Libxml2 2.5.4 XMLSoft Libxml2 2.5.1 XMLSoft Libxml2 2.4.30 XMLSoft Libxml2 2.4.29 XMLSoft Libxml2 2.4.28 XMLSoft Libxml2 2.4.27 XMLSoft Libxml2 2.4.26 XMLSoft Libxml2 2.4.24 XMLSoft Libxml2 2.4.23 XMLSoft Libxml2 2.4.22 XMLSoft Libxml2 2.4.21 XMLSoft Libxml2 2.4.20 XMLSoft Libxml2 2.4.19 XMLSoft Libxml2 2.4.18 XMLSoft Libxml2 2.4.17 XMLSoft Libxml2 2.4.16 XMLSoft Libxml2 2.4.15 XMLSoft Libxml2 2.4.14 XMLSoft Libxml2 2.4.13 XMLSoft Libxml2 2.4.12 XMLSoft Libxml2 2.4.11 XMLSoft Libxml2 2.4.10 XMLSoft Libxml2 2.4.9 XMLSoft Libxml2 2.4.8 XMLSoft Libxml2 2.4.7 XMLSoft Libxml2 2.4.6 XMLSoft Libxml2 2.4.5 XMLSoft Libxml2 2.4.4 XMLSoft Libxml2 2.4.3 XMLSoft Libxml2 2.4.2 XMLSoft Libxml2 2.3.14 XMLSoft Libxml2 2.3.13 XMLSoft Libxml2 2.3.12 XMLSoft Libxml2 2.3.10 XMLSoft Libxml2 2.3.8 XMLSoft Libxml2 2.3.7 XMLSoft Libxml2 2.3.6 XMLSoft Libxml2 2.3.5 XMLSoft Libxml2 2.3.4 XMLSoft Libxml2 2.2.11 XMLSoft Libxml2 2.2.10 XMLSoft Libxml2 2.2.7 XMLSoft Libxml2 2.2.6 XMLSoft Libxml2 2.2.5 XMLSoft Libxml2 2.2.4 XMLSoft Libxml2 2.2.3 XMLSoft Libxml2 1.8.14 XMLSoft Libxml2 1.8.10 XMLSoft Libxml2 1.8.9 XMLSoft Libxml2 1.8.5 XMLSoft Libxml2 1.8.4 XMLSoft Libxml2 1.8.3 XMLSoft Libxml2 1.8.1 XMLSoft Libxml2 1.7.4 XMLSoft Libxml2 1.7 XMLSoft Libxml2 2.6.27 XMLSoft Libxml2 2.6.0 XMLSoft Libxml2 2.5.7 XMLSoft Libxml2 2.5.0 XMLSoft Libxml2 2.4.25 XMLSoft Libxml2 2.4.1 XMLSoft Libxml2 2.3.3 XMLSoft Libxml2 2.3.2 XMLSoft Libxml2 2.3.11 XMLSoft Libxml2 2.3.1 XMLSoft Libxml2 2.3.0 XMLSoft Libxml2 2.2.9 XMLSoft Libxml2 2.2.8 XMLSoft Libxml2 2.2.2 XMLSoft Libxml2 2.2.1 XMLSoft Libxml2 2.2.0 XMLSoft Libxml2 2.1.1 XMLSoft Libxml2 2.1.0 XMLSoft Libxml2 2.0.0 XMLSoft Libxml2 1.8.7 XMLSoft Libxml2 1.8.6 XMLSoft Libxml2 1.8.16 XMLSoft Libxml2 1.8.13 XMLSoft Libxml2 1.7.3 XMLSoft Libxml2 1.7.2 XMLSoft Libxml2 1.7.1 VMWare ESXi 5.0 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM Aix 7.1.1 IBM Aix 7.1 IBM Aix 6.1.7 IBM Aix 6.1.6 IBM AIX 6.1.5 IBM AIX 6.1.4 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 7.1 IBM AIX 6.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Avaya Aura System Manager 6.2 Avaya Aura Session Manager 6.2 Avaya Aura Presence Services 6.1 Avaya Aura Experience Portal 6.0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 Apple Apple TV 5.0 Apple Apple TV 4.4 Apple Apple TV 4.3 Apple Apple TV 4.2 Apple Apple TV 4.1 Apple Apple TV 4.0 |
| Not Vulnerable: | |
Discussion
Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
Libxml2 is prone to a denial-of-service vulnerability.
Successful exploits will allow attackers to consume large amounts of CPU, and memory and cause a crash through a specially crafted XML containing malicious attributes.
Libxml2 is prone to a denial-of-service vulnerability.
Successful exploits will allow attackers to consume large amounts of CPU, and memory and cause a crash through a specially crafted XML containing malicious attributes.
Exploit / POC
Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability
References:
References:
- Apple iOS Homepage (Apple)
- Apple Mac OS X Homepage (Apple)
- Bug 1090976 - (CVE-2014-0191) CVE-2014-0191 libxml2: external parameter entity l (Red Hat Bugzilla)
- Do not fetch external parameter entities (xmlsoft)
- iPad Homepage (Apple)
- iPhone Homepage (Apple)
- iPod touch Product Page (Apple)
- AIX libxml2 vulnerability (IBM)
- ASA-2015-075 (Avaya)
- IBM Advisory MIGR-5098592 (IBM)
- InfoSphere Streams is affected by libxml2 vulnerability (CVE-2014-0191) (IBM)
- libxml2 security update (RHSA-2014-0513) (Avaya)
- Oracle Critical Patch Update Advisory - January 2015 Oracle Advisory (Oracle)
- Security Bulletin: IBM Docs fixes for vulnerabilities in Open Source libxml2 (CV (IBM)
- Security Bulletin: Rational Systems Tester is affected by Libxml2 vulnerability (IBM)
- Security Bulletin: Vulnerabilities affect IBM's AMM (IBM)
- Security Bulletin: Vulnerabilities in libxml2 affect System Networking Products (IBM)
- Security Bulletin: Vulnerability in Libxml2 affects IBM Endpoint Manager for Sec (IBM)
- VMware Security Advisories Security VMSA-2014-0012 (VMware)
- Vulnerabilities in Libxml2 affect System x Integrated Management Module (IMM) (C (IBM)