CVE-2015-3451

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
References
Link Resource
http://advisories.mageia.org/MGASA-2015-0199.html Third Party Advisory
http://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changes Release Notes Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2015-09/msg00006.html Third Party Advisory
http://www.debian.org/security/2015/dsa-3243 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2015:231 Broken Link
http://www.openwall.com/lists/oss-security/2015/04/25/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/04/30/1 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/74333 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-2592-1 Third Party Advisory
https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/ Vendor Advisory
http://advisories.mageia.org/MGASA-2015-0199.html Third Party Advisory
http://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changes Release Notes Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2015-09/msg00006.html Third Party Advisory
http://www.debian.org/security/2015/dsa-3243 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2015:231 Broken Link
http://www.openwall.com/lists/oss-security/2015/04/25/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/04/30/1 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/74333 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-2592-1 Third Party Advisory
https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xml-libxml_project:xml-libxml:*:*:*:*:*:perl:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:29

Type Values Removed Values Added
References () http://advisories.mageia.org/MGASA-2015-0199.html - Third Party Advisory () http://advisories.mageia.org/MGASA-2015-0199.html - Third Party Advisory
References () http://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changes - Release Notes, Third Party Advisory () http://cpansearch.perl.org/src/SHLOMIF/XML-LibXML-2.0119/Changes - Release Notes, Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157448.html - Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157740.html - Third Party Advisory
References () http://lists.opensuse.org/opensuse-updates/2015-09/msg00006.html - Third Party Advisory () http://lists.opensuse.org/opensuse-updates/2015-09/msg00006.html - Third Party Advisory
References () http://www.debian.org/security/2015/dsa-3243 - Third Party Advisory () http://www.debian.org/security/2015/dsa-3243 - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2015:231 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2015:231 - Broken Link
References () http://www.openwall.com/lists/oss-security/2015/04/25/2 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/04/25/2 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2015/04/30/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/04/30/1 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/74333 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/74333 - Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-2592-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-2592-1 - Third Party Advisory
References () https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/ - Vendor Advisory () https://bitbucket.org/shlomif/perl-xml-libxml/commits/5962fd067580767777e94640b129ae8930a68a30/raw/ - Vendor Advisory

Information

Published : 2015-05-12 19:59

Updated : 2024-11-21 02:29


NVD link : CVE-2015-3451

Mitre link : CVE-2015-3451

CVE.ORG link : CVE-2015-3451


JSON object : View

Products Affected

opensuse

  • opensuse

xml-libxml_project

  • xml-libxml

canonical

  • ubuntu_linux

debian

  • debian_linux

fedoraproject

  • fedora
CWE
CWE-611

Improper Restriction of XML External Entity Reference