CVE-2016-9318: XEE
Last updated 25 August 2025
Other sources
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-9318?
CVE-2016-9318 is a vulnerability in libxml2 version 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, that allows remote attackers to conduct XML External Entity (XXE) attacks.
How severe is CVE-2016-9318?
CVE-2016-9318 has a severity rating of 5.5 (medium).
Which versions of libxml2 are affected by CVE-2016-9318?
Versions 2.9.4 and earlier of libxml2 are affected by CVE-2016-9318.
How can I fix CVE-2016-9318 in libxml2?
To fix CVE-2016-9318 in libxml2, you should update to version 2.9.4+dfsg1-6.1ubuntu1.2 or later.
Where can I find more information about CVE-2016-9318?
You can find more information about CVE-2016-9318 at the following references: [Bugzilla](https://bugzilla.gnome.org/show_bug.cgi?id=772726), [GitHub](https://github.com/lsh123/xmlsec/issues/43), [SecurityFocus](http://www.securityfocus.com/bid/94347).