A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1950515 | Issue Tracking Patch Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20210805-0007/ | |
| https://www.oracle.com/security-alerts/cpujan2022.html |
Information
Published : 2021-07-09 17:15
Updated : 2022-02-07 16:16
NVD link : CVE-2021-3541
Mitre link : CVE-2021-3541
JSON object : View
Products Affected
xmlsoft
- libxml2
redhat
- jboss_core_services
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
