XXE attack in Libxml2 - CVE-2017-7375
Published: March 22, 2018
Vulnerability identifier: #VU11229
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7375
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to perform XXE attack on the target system.
The weakness exists in the xmlParsePEReference function due to insufficient validation for external entities. A remote attacker can perform XXE attack and gain access to potentially sensitive information.
The weakness exists in the xmlParsePEReference function due to insufficient validation for external entities. A remote attacker can perform XXE attack and gain access to potentially sensitive information.
Affected software
Libxml2
Gentoo Linux
App Connect Enterprise Certified Container
Gentoo Linux
App Connect Enterprise Certified Container
How to mitigate CVE-2017-7375
Update to version 2.9.5 or later.
App Connect Enterprise Certified Container - addressed in versions 5.0.1, 6.1.0