CVE-2017-1000061
17.07.2017, 13:18
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of serviceEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xmlsec_project | xmlsec | 𝑥 ≤ 1.2.23 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xmlsec1 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| xmlsec1 |
| ||
| xmlsec1-devel |
| ||
| xmlsec1-gcrypt |
| ||
| xmlsec1-gcrypt-devel |
| ||
| xmlsec1-gnutls |
| ||
| xmlsec1-gnutls-devel |
| ||
| xmlsec1-nss |
| ||
| xmlsec1-nss-devel |
| ||
| xmlsec1-openssl |
| ||
| xmlsec1-openssl-devel |
|
References