Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libxml2 数字错误漏洞
Vulnerability Description
libxml2是开源的一个用来解析XML文档的函数库。它用C语言写成,并且能为多种语言所调用,例如C语言,C++,XSH。 libxml2 2.5.0之前版本存在数字错误漏洞,该漏洞源于在实体扩展期间无法正确检测递归,允许上下文相关攻击者通过包含大量嵌套实体引用的构建 XML 文档造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A