Expat Entity Expansion 权限许可和访问控制问题漏洞

admin 2022-07-24 09:07:10 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Expat Entity Expansion 权限许可和访问控制问题漏洞

  • CNNVD编号:CNNVD-201303-096
  • 危害等级: 中危
  • CVE编号: CVE-2013-0340
  • 漏洞类型: 代码问题
  • 发布时间: 2013-02-21
  • 威胁类型: 远程
  • 更新时间: 2021-11-01
  • 厂        商: libexpat
  • 漏洞来源:

漏洞简介

Expat是美国软件开发者吉姆-克拉克所研发的一个基于C语言的XML解析器库,它采用了一个面向流的解析器。

expat 2.1.0及之前的版本中存在远程拒绝服务漏洞。当程序处理XML Internal Entities扩展时,远程攻击者可借助恶意的XML文档利用该漏洞造成拒绝服务(资源消耗),向内网服务器发送HTTP请求,或读取任意文件。

漏洞公告

目前厂商还没有提供此漏洞的相关补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:

http://www.libexpat.org/

参考网址

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Oct/63

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Oct/62

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/39

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212805

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/38

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212804

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/35

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/34

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/33

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212807

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2013/04/12/6

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Oct/61

来源:MLIST

链接:https://lists.apache.org/thread.HTML/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702@%3Cusers.openoffice.apache.org%3E

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2021/10/07/4

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212815

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212814

来源:CONFIRM

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212819

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2021/Sep/40

来源:MLIST

链接:https://lists.apache.org/thread.HTML/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d@%3Cannounce.apache.org%3E

来源:BID

链接:https://www.securityfocus.com/bid/58233

来源:GENTOO

链接:https://security.gentoo.org/glsa/201701-21

来源:OSVDB

链接:http://www.osvdb.org/90634

来源:SECTRACK

链接:http://securitytracker.com/id?1028213

来源:BID

链接:http://www.securityfocus.com/bid/58233

来源:MLIST

链接:http://openwall.com/lists/oss-security/2013/02/22/3

来源:www.ibm.com

链接:http://www.ibm.com/support/docview.wss?uid=swg22010778

来源:www.cybersecurity-help.cz

链接:https://www.cybersecurity-help.cz/vdb/SB2021052301

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.3155

来源:support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com

链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/en-us/HT212815

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/164249/CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-Security-Advisory-2021-09-20-8.HTML

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.3578

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2136/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/164692/CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-Security-Advisory-2021-10-26-10.HTML

来源:www.cybersecurity-help.cz

链接:https://www.cybersecurity-help.cz/vdb/SB2021092024

受影响实体

  • Libexpat Expat:2.0.1  
  • Libexpat Expat:2.0.0  
  • Libexpat Expat:1.95.8  
  • Libexpat Expat:1.95.7  
  • Libexpat Expat:1.95.6  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0