Oval Definition:oval:org.mitre.oval:def:20018
Revision Date:2014-06-23Version:6
Title:DSA-2652-1 libxml2 - external entity expansion
Description:Brad Hill of iSEC Partners discovered that many XML implementations are vulnerable to external entity expansion issues, which can be used for various purposes such as firewall circumvention, disguising an IP address, and denial-of-service. libxml2 was susceptible to these problems when performing string substitution during entity expansion.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-0338
CVE-2013-0339
DSA-2652-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):libxml2
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND libxml2 DPKG is earlier than 0:2.7.8.dfsg-2+squeeze7
  • BACK