CVE-2013-0338
Publication date 26 February 2013
Last updated 24 July 2024
Ubuntu priority
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
Status
Package | Ubuntu Release | Status |
---|---|---|
libxml2 | ||
Notes
Patch details
Package | Patch details |
---|---|
libxml2 |
|
References
Related Ubuntu Security Notices (USN)
- USN-1782-1
- libxml2 vulnerability
- 28 March 2013