CVE-2013-0338

EUVD-2013-0350
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxml2
𝑥
≤ 2.9.0
xmlsoftlibxml2
1.7.0
xmlsoftlibxml2
1.7.1
xmlsoftlibxml2
1.7.2
xmlsoftlibxml2
1.7.3
xmlsoftlibxml2
1.7.4
xmlsoftlibxml2
1.8.0
xmlsoftlibxml2
1.8.1
xmlsoftlibxml2
1.8.2
xmlsoftlibxml2
1.8.3
xmlsoftlibxml2
1.8.4
xmlsoftlibxml2
1.8.5
xmlsoftlibxml2
1.8.6
xmlsoftlibxml2
1.8.7
xmlsoftlibxml2
1.8.9
xmlsoftlibxml2
1.8.10
xmlsoftlibxml2
1.8.13
xmlsoftlibxml2
1.8.14
xmlsoftlibxml2
1.8.16
xmlsoftlibxml2
2.0.0
xmlsoftlibxml2
2.1.0
xmlsoftlibxml2
2.1.1
xmlsoftlibxml2
2.2.0
xmlsoftlibxml2
2.2.0:beta
xmlsoftlibxml2
2.2.1
xmlsoftlibxml2
2.2.2
xmlsoftlibxml2
2.2.3
xmlsoftlibxml2
2.2.4
xmlsoftlibxml2
2.2.5
xmlsoftlibxml2
2.2.6
xmlsoftlibxml2
2.2.7
xmlsoftlibxml2
2.2.8
xmlsoftlibxml2
2.2.9
xmlsoftlibxml2
2.2.10
xmlsoftlibxml2
2.2.11
xmlsoftlibxml2
2.3.0
xmlsoftlibxml2
2.3.1
xmlsoftlibxml2
2.3.2
xmlsoftlibxml2
2.3.3
xmlsoftlibxml2
2.3.4
xmlsoftlibxml2
2.3.5
xmlsoftlibxml2
2.3.6
xmlsoftlibxml2
2.3.7
xmlsoftlibxml2
2.3.8
xmlsoftlibxml2
2.3.9
xmlsoftlibxml2
2.3.10
xmlsoftlibxml2
2.3.11
xmlsoftlibxml2
2.3.12
xmlsoftlibxml2
2.3.13
xmlsoftlibxml2
2.3.14
xmlsoftlibxml2
2.4.1
xmlsoftlibxml2
2.4.2
xmlsoftlibxml2
2.4.3
xmlsoftlibxml2
2.4.4
xmlsoftlibxml2
2.4.5
xmlsoftlibxml2
2.4.6
xmlsoftlibxml2
2.4.7
xmlsoftlibxml2
2.4.8
xmlsoftlibxml2
2.4.9
xmlsoftlibxml2
2.4.10
xmlsoftlibxml2
2.4.11
xmlsoftlibxml2
2.4.12
xmlsoftlibxml2
2.4.13
xmlsoftlibxml2
2.4.14
xmlsoftlibxml2
2.4.15
xmlsoftlibxml2
2.4.16
xmlsoftlibxml2
2.4.17
xmlsoftlibxml2
2.4.18
xmlsoftlibxml2
2.4.19
xmlsoftlibxml2
2.4.20
xmlsoftlibxml2
2.4.21
xmlsoftlibxml2
2.4.22
xmlsoftlibxml2
2.4.23
xmlsoftlibxml2
2.4.24
xmlsoftlibxml2
2.4.25
xmlsoftlibxml2
2.4.26
xmlsoftlibxml2
2.4.27
xmlsoftlibxml2
2.4.28
xmlsoftlibxml2
2.4.29
xmlsoftlibxml2
2.4.30
xmlsoftlibxml2
2.5.0
xmlsoftlibxml2
2.5.4
xmlsoftlibxml2
2.5.7
xmlsoftlibxml2
2.5.8
xmlsoftlibxml2
2.5.10
xmlsoftlibxml2
2.5.11
xmlsoftlibxml2
2.6.0
xmlsoftlibxml2
2.6.1
xmlsoftlibxml2
2.6.2
xmlsoftlibxml2
2.6.3
xmlsoftlibxml2
2.6.4
xmlsoftlibxml2
2.6.5
xmlsoftlibxml2
2.6.6
xmlsoftlibxml2
2.6.7
xmlsoftlibxml2
2.6.8
xmlsoftlibxml2
2.6.9
xmlsoftlibxml2
2.6.11
xmlsoftlibxml2
2.6.12
xmlsoftlibxml2
2.6.13
xmlsoftlibxml2
2.6.14
xmlsoftlibxml2
2.6.16
xmlsoftlibxml2
2.6.17
xmlsoftlibxml2
2.6.18
xmlsoftlibxml2
2.6.20
xmlsoftlibxml2
2.6.21
xmlsoftlibxml2
2.6.22
xmlsoftlibxml2
2.6.23
xmlsoftlibxml2
2.6.24
xmlsoftlibxml2
2.6.25
xmlsoftlibxml2
2.6.26
xmlsoftlibxml2
2.6.27
xmlsoftlibxml2
2.6.28
xmlsoftlibxml2
2.6.29
xmlsoftlibxml2
2.6.30
xmlsoftlibxml2
2.6.31
xmlsoftlibxml2
2.6.32
xmlsoftlibxml2
2.7.0
xmlsoftlibxml2
2.7.1
xmlsoftlibxml2
2.7.2
xmlsoftlibxml2
2.7.3
xmlsoftlibxml2
2.7.4
xmlsoftlibxml2
2.7.5
xmlsoftlibxml2
2.7.6
xmlsoftlibxml2
2.7.7
xmlsoftlibxml2
2.7.8
xmlsoftlibxml2
2.9.0:rc1
canonicalubuntu_linux
8.04
canonicalubuntu_linux
10.04
canonicalubuntu_linux
11.10
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
opensuseopensuse
12.1
opensuseopensuse
12.2
opensuseopensuse
12.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml2
hardy
Fixed 2.6.31.dfsg-2ubuntu1.12
released
lucid
Fixed 2.7.6.dfsg-1ubuntu1.8
released
oneiric
Fixed 2.7.8.dfsg-4ubuntu0.6
released
precise
Fixed 2.7.8.dfsg-5.1ubuntu4.4
released
quantal
Fixed 2.8.0+dfsg1-5ubuntu2.2
released