CVE-2016-9318 PUBLISHED

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

EPSS 0.13% · 32.7th percentile

Risk Scores

EPSS Score
0.13%
32.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxml20, 2.9.1+dfsg1-3ubuntu2, 2.9.1+dfsg1-3ubuntu3
Ubuntu:16.04:LTSlibxml20, 2.9.2+zdfsg1-4, 2.9.2+zdfsg1-4ubuntu1
Ubuntu:18.04:LTSlibxml20, 2.9.4+dfsg1-4ubuntu1, 2.9.4+dfsg1-5ubuntu1

Timeline

References

Open in Interactive Console →