Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libxml2 输入验证错误漏洞
Vulnerability Description
Libxml2是GNOME项目组所研发的一个基于C语言的用来解析XML文档的函数库,它支持多种编码格式、Xpath解析、Well-formed和valid验证等。 Libxml2 2.9.3及之前版本的parser.c文件中的‘xmlStringLenDecodeEntities’函数存在XML外部实体漏洞。当程序没有处于验证模式时,攻击者可利用该漏洞读取任意文件或造成拒绝服务(资源消耗)。
CVSS Information
N/A
Vulnerability Type
N/A