REDHAT-BUG-461107: Medium severity libxml2 vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2003-1564 to the following vulnerability:
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
References: http://www.stylusstudio.com/xmldev/200302/post20020.html http://www.reddit.com/r/programming/comments/65843/timetoupgradelibxml2 http://xmlsoft.org/news.html http://mail.gnome.org/archives/xml/2008-August/msg00034.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-461107?
The severity of REDHAT-BUG-461107 is identified as critical due to its potential to allow Denial of Service through XML entity expansion.
How do I fix REDHAT-BUG-461107?
To fix REDHAT-BUG-461107, upgrade libxml2 to version 2.5.0 or later, where the vulnerability has been addressed.
What versions of libxml2 are affected by REDHAT-BUG-461107?
Versions of libxml2 prior to 2.5.0 are affected by REDHAT-BUG-461107 and may be susceptible to the vulnerability.
What impact does the vulnerability identified by REDHAT-BUG-461107 have?
The impact of the vulnerability identified by REDHAT-BUG-461107 can lead to denial of service due to excessive resource consumption during XML parsing.
Is the vulnerability REDHAT-BUG-461107 related to XML parsing?
Yes, the vulnerability REDHAT-BUG-461107 specifically relates to improper recursion detection during XML entity expansion.