CVE-2017-1000061: XEE
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
Other sources
xmlsec is vulnerable to XML External Entity Expansion via libxml2 (see CVE-2016-9318). A workaround is in progress on the upstream bug report.
Upstream bug:
https://github.com/lsh123/xmlsec/issues/43
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000061?
CVE-2017-1000061 is classified as a medium severity vulnerability.
How does CVE-2017-1000061 affect xmlsec?
CVE-2017-1000061 affects xmlsec by allowing XML External Entity Expansion, which can lead to information disclosure or denial of service.
What versions of xmlsec are impacted by CVE-2017-1000061?
CVE-2017-1000061 impacts xmlsec versions 1.2.23 and earlier.
How can I mitigate the risk of CVE-2017-1000061?
To mitigate the risk of CVE-2017-1000061, upgrade to xmlsec version 1.2.24 or later.
Is there a workaround for CVE-2017-1000061 if immediate updating is not possible?
If immediate updating for CVE-2017-1000061 is not possible, avoid parsing untrusted XML input as a temporary workaround.