REDHAT-BUG-461107: Medium severity libxml2 vulnerability

Published Sep 4, 2008
·
Updated

Common Vulnerabilities and Exposures assigned an identifier CVE-2003-1564 to the following vulnerability:

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

References: http://www.stylusstudio.com/xmldev/200302/post20020.html http://www.reddit.com/r/programming/comments/65843/timetoupgradelibxml2 http://xmlsoft.org/news.html http://mail.gnome.org/archives/xml/2008-August/msg00034.html

Affected Software

1 affected component
Gnome libxml2<2.5.0

Event History

Sep 4, 2008
Data Sourced
via Red Hat·08:54 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-461107?

The severity of REDHAT-BUG-461107 is identified as critical due to its potential to allow Denial of Service through XML entity expansion.

2

How do I fix REDHAT-BUG-461107?

To fix REDHAT-BUG-461107, upgrade libxml2 to version 2.5.0 or later, where the vulnerability has been addressed.

3

What versions of libxml2 are affected by REDHAT-BUG-461107?

Versions of libxml2 prior to 2.5.0 are affected by REDHAT-BUG-461107 and may be susceptible to the vulnerability.

4

What impact does the vulnerability identified by REDHAT-BUG-461107 have?

The impact of the vulnerability identified by REDHAT-BUG-461107 can lead to denial of service due to excessive resource consumption during XML parsing.

5

Is the vulnerability REDHAT-BUG-461107 related to XML parsing?

Yes, the vulnerability REDHAT-BUG-461107 specifically relates to improper recursion detection during XML entity expansion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203