Denial of Service Vulnerability in libxml2 Affecting Multiple Vendors
CVE-2021-3541

6.5MEDIUM

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
9 July 2021

What is CVE-2021-3541?

A critical flaw has been identified in libxml2 that allows an exponential entity expansion attack, potentially circumventing all existing protective measures. This vulnerability can lead to significant service interruptions, prompting immediate attention from users relying on this library. The affected versions prior to 2.9.10 lack adequate defenses against this exploit, making them susceptible to denial of service attacks. Organizations should prioritize updating to secure versions and review their implementations to mitigate risk.

Affected Version(s)

libxml2 2.9.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.