« List of all CVEs

CVE-2013-0340

Published: 1/21/2014 Last updated: 8/6/2024 Reserved: 12/6/2012

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (11)

conf-expat conf-gtk2 conf-gtk3 conf-python-2-7 conf-python-2-7-dev conf-python-3 conf-python-3-7 conf-python-3-dev ocaml-expat py termbox

Products affected (1)

Product Vendor Version
n/a n/a < 6.2.9200.24821

References (48)