CVE-2014-3660
CVE-2014-3660
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1655.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1885.htmlhttps://bugzilla.redhat.com/attachment.cgi?id=944444&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=1149084http://secunia.com/advisories/59903http://secunia.com/advisories/61965http://secunia.com/advisories/61966