← Back

CVE-2017-7375

nvd nist
Published: Feb 19, 2018Modified: Dec 3, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).

Affected (14)

1 product
Libxml2
1 product
Debian Linux
1 product
Android
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.9.4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Version 9.0
Configuration C
8 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 4.4.4
Version 5.0.2
Version 5.1.1
Version 6.0.1
Version 6.0
Version 7.0
Version 7.1.1
Version 7.1.2
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Xmlsoft
Version 2.9.4 rc1
Version 2.9.4 rc2

References (16)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.