Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libxml2 拒绝服务漏洞
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 libxml2 2.9.2之前版本的parser.c脚本中存在安全漏洞,该漏洞源于程序禁用实体替换时,没有正确处理实体扩展。攻击者可借助带有大量嵌套实体引用的XML文档利用该漏洞造成拒绝服务(CPU消耗)。
CVSS Information
N/A
Vulnerability Type
N/A