![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2017-7375 |
Description: | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher- risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable). |
Test IDs: | 1.3.6.1.4.1.25623.1.1.2.2018.1336 1.3.6.1.4.1.25623.1.1.4.2017.2701.1 1.3.6.1.4.1.25623.1.0.891008 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-7375 BugTraq ID: 98877 http://www.securityfocus.com/bid/98877 Debian Security Information: DSA-3952 (Google Search) https://www.debian.org/security/2017/dsa-3952 https://security.gentoo.org/glsa/201711-01 http://www.securitytracker.com/id/1038623 |