CVE-2015-3451

Publication date 1 May 2015

Last updated 24 July 2024


Ubuntu priority

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

Status

Package Ubuntu Release Status
libxml-libxml-perl 15.04 vivid
Fixed 2.0116+dfsg-1ubuntu0.15.04.1
14.10 utopic
Fixed 2.0116+dfsg-1ubuntu0.14.10.1
14.04 LTS trusty
Fixed 2.0108+dfsg-1ubuntu0.1
12.04 LTS precise
Fixed 1.89+dfsg-1ubuntu0.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libxml-libxml-perl

References

Related Ubuntu Security Notices (USN)

Other references