CVE-2024-40896
Ubuntu Security Notice USN-7215-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
En libxml2 2.11 anterior a 2.11.9, 2.12 anterior a 2.12.9 y 2.13 anterior a 2.13.3, el analizador SAX puede producir eventos para entidades externas incluso si los controladores SAX personalizados intentan anular el contenido de la entidad (estableciendo "marcado"). Esto hace posibles los ataques XXE clásicos.
Xisco Fauli discovered that libxml2 incorrectly handled custom SAX handlers. A remote attacker could possibly use this issue to perform XML External Entity attacks.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-07-12 CVE Reserved
- 2024-12-23 CVE Published
- 2024-12-24 CVE Updated
- 2024-12-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 | ||
https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libxml2 Search vendor "Libxml2" | Libxml2 Search vendor "Libxml2" for product "Libxml2" | >= 2.11.0 < 2.11.9 Search vendor "Libxml2" for product "Libxml2" and version " >= 2.11.0 < 2.11.9" | en |
Affected
| ||||||
Libxml2 Search vendor "Libxml2" | Libxml2 Search vendor "Libxml2" for product "Libxml2" | >= 2.12.0 < 2.12.9 Search vendor "Libxml2" for product "Libxml2" and version " >= 2.12.0 < 2.12.9" | en |
Affected
| ||||||
Libxml2 Search vendor "Libxml2" | Libxml2 Search vendor "Libxml2" for product "Libxml2" | >= 2.13.0 < 2.13.3 Search vendor "Libxml2" for product "Libxml2" and version " >= 2.13.0 < 2.13.3" | en |
Affected
|