CVE-2008-3281
27.08.2008, 20:41
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
Vendor | Product | Version |
---|---|---|
xmlsoft | libxml2 | 𝑥 ≤ 2.6.32 |
apple | safari | 𝑥 < 4.0 |
apple | iphone_os | 1.0.0 ≤ 𝑥 < 3.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
debian | debian_linux | 4.0 |
redhat | enterprise_linux_desktop | 3.0 |
redhat | enterprise_linux_desktop | 4.0 |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_eus | 4.7 |
redhat | enterprise_linux_eus | 5.2 |
redhat | enterprise_linux_server | 2.0 |
redhat | enterprise_linux_server | 3.0 |
redhat | enterprise_linux_server | 4.0 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_workstation | 2.0 |
redhat | enterprise_linux_workstation | 3.0 |
redhat | enterprise_linux_workstation | 4.0 |
redhat | enterprise_linux_workstation | 5.0 |
vmware | esx | 2.5.4 |
vmware | esx | 2.5.5 |
vmware | esx | 3.0.2 |
vmware | esx | 3.0.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References