CVE-2014-3660
Description
libxml2 before 2.9.2 fails to restrict entity expansion even when substitution is disabled, leading to CPU exhaustion via crafted XML.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
libxml2 before 2.9.2 fails to restrict entity expansion even when substitution is disabled, leading to CPU exhaustion via crafted XML.
Vulnerability
The vulnerability resides in parser.c of libxml2 versions prior to 2.9.2. When parsing XML, the library does not properly limit entity expansion even when entity substitution has been disabled, allowing a crafted document with deeply nested entity references to consume excessive CPU resources [1][4].
Exploitation
An attacker can exploit this by providing a specially crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack. No authentication or special access is required; the attacker only needs to supply the malicious input to any application that processes XML using a vulnerable version of libxml2.
Impact
Successful exploitation causes high CPU consumption, resulting in a denial of service (DoS) condition. The attack can make the affected application or system unresponsive.
Mitigation
The fixed version is libxml2 2.9.2 [1][4]. Red Hat has released updated packages (e.g., libxml2-2.9.1-5.el7_0.1) for Red Hat Enterprise Linux 7 [1][4]. Apple also addressed this issue in OS X Yosemite v10.10.5 and Security Update 2015-006 [2]. Users should upgrade to the latest patched version.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
118cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*+ 109 more
- cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*range: <=2.9.1
- cpe:2.3:a:xmlsoft:libxml2:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.0:beta:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.11:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.12:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.13:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.14:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.11:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.12:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.13:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.14:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.15:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.16:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.17:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.18:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.19:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.20:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.21:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.22:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.23:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.24:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.25:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.26:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.27:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.28:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.29:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.30:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.11:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.5.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.12:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.13:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.14:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.16:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.17:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.18:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.20:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.21:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.22:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.23:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.24:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.25:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.26:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.27:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.28:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.29:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.30:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.31:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.32:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.9:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.7:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.9.0:rc1:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
- Range: <2.9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
23- www.openwall.com/lists/oss-security/2014/10/17/7nvdPatch
- www.ubuntu.com/usn/USN-2389-1nvdVendor Advisory
- support.apple.com/kb/HT205030nvdVendor Advisory
- support.apple.com/kb/HT205031nvdVendor Advisory
- kb.juniper.net/InfoCenter/indexnvd
- lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlnvd
- lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-10/msg00034.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-12/msg00120.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1655.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1885.htmlnvd
- secunia.com/advisories/59903nvd
- secunia.com/advisories/61965nvd
- secunia.com/advisories/61966nvd
- secunia.com/advisories/61991nvd
- www.debian.org/security/2014/dsa-3057nvd
- www.mandriva.com/security/advisoriesnvd
- www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlnvd
- www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlnvd
- www.securityfocus.com/bid/70644nvd
- bugzilla.redhat.com/attachment.cginvd
- bugzilla.redhat.com/show_bug.cginvd
- www.ncsc.nl/actueel/nieuwsberichten/kwetsbaarheid-ontdekt-in-libxml2.htmlnvd
News mentions
0No linked articles in our index yet.