CVE-2013-0340
Description
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
Affected products
7Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
25- openwall.com/lists/oss-security/2013/02/22/3nvdExploitMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Oct/61nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Oct/62nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Oct/63nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/33nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/34nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/35nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/38nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/39nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Sep/40nvdMailing ListThird Party Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.openwall.com/lists/oss-security/2013/04/12/6nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/10/07/4nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/58233nvdBroken LinkThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201701-21nvdThird Party Advisory
- support.apple.com/kb/HT212804nvdThird Party Advisory
- support.apple.com/kb/HT212805nvdThird Party Advisory
- support.apple.com/kb/HT212807nvdThird Party Advisory
- support.apple.com/kb/HT212814nvdThird Party Advisory
- support.apple.com/kb/HT212815nvdThird Party Advisory
- support.apple.com/kb/HT212819nvdThird Party Advisory
- www.osvdb.org/90634nvdBroken Link
- github.com/libexpat/libexpat/blob/R_2_4_1/expat/Changesnvd
- lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d%40%3Cannounce.apache.org%3Envd
- lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3Envd
News mentions
0No linked articles in our index yet.