XML External Entity injection in Libxml2 - CVE-2016-9318
Published: November 16, 2016 / Updated: July 24, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Affected software
Gentoo Linux
libxml2 (Alpine package)
Integrated Management Module II (IMM2)
Flex System Chassis Management Module (CMM)
IBM RackSwitch G7028
IBM RackSwitch G8052
IBM RackSwitch G8124
IBM RackSwitch G8124E
How to mitigate CVE-2016-9318
Integrated Management Module II (IMM2) - addressed in versions 1AOO80G-6.40, 1AOO80G-6.40_bc
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
IBM RackSwitch G7028 - update to 7.6.8.0
IBM RackSwitch G8052 - update to 7.11.20.0
IBM RackSwitch G8124 - update to 7.11.20.0
IBM RackSwitch G8124E - update to 7.11.20.0
External References
Related Security Bulletins
- XML External Entity injection in Libxml2
- XML External Entity injection in libxml2 (Alpine package)
- Gentoo update for libxml2
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter Systems
- IBM RackSwitch firmware update for Libxml2
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)