XML External Entity injection in Libxml2 - CVE-2016-9318

 

XML External Entity injection in Libxml2 - CVE-2016-9318

Published: November 16, 2016 / Updated: July 24, 2020


Vulnerability identifier: #VU31830
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9318
CWE-ID: CWE-611
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.


Affected software

Libxml2
Gentoo Linux
libxml2 (Alpine package)
Integrated Management Module II (IMM2)
Flex System Chassis Management Module (CMM)
IBM RackSwitch G7028
IBM RackSwitch G8052
IBM RackSwitch G8124
IBM RackSwitch G8124E

How to mitigate CVE-2016-9318

Install update from vendor's website.

libxml2 (Alpine package) - update to 2.9.4-r2
Integrated Management Module II (IMM2) - addressed in versions 1AOO80G-6.40, 1AOO80G-6.40_bc
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
IBM RackSwitch G7028 - update to 7.6.8.0
IBM RackSwitch G8052 - update to 7.11.20.0
IBM RackSwitch G8124 - update to 7.11.20.0
IBM RackSwitch G8124E - update to 7.11.20.0

External References

Related Security Bulletins