CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxml2
𝑥
≤ 2.9.4
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
googleandroid
4.4.4
googleandroid
5.0.2
googleandroid
5.1.1
googleandroid
6.0
googleandroid
6.0.1
googleandroid
7.0
googleandroid
7.1.1
googleandroid
7.1.2
xmlsoftlibxml2
2.9.4:rc1
xmlsoftlibxml2
2.9.4:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml2
trusty
Fixed 2.9.1+dfsg1-3ubuntu4.10
released
xenial
Fixed 2.9.3+dfsg1-1ubuntu0.3
released
yakkety
ignored
zesty
Fixed 2.9.4+dfsg1-2.2ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxml2-2
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-2-32bit
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-doc
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
libxml2-tools
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise sap 12 SP5
2.9.4-46.20.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP5
2.9.4-46.20.1
fixed
python-libxml2
suse enterprise sap 12 SP2
2.9.4-45.1
fixed
suse enterprise server 12 SP2
2.9.4-45.1
fixed