Sploitus

CVE-2014-3660

2 known exploits for CVE-2014-3660

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

Affected products
Alt Linux, Centos, Red Hat, Suse, Ubuntu, Libxml2
Xmlsoft libxml2
≤ 2.9.1, 2.0.0, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 2.2.10, 2.2.11, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9
CVSS 2.0
5.0 MEDIUM
EPSS
4.0% (90th percentile)
NVD status
Modified
Published
2014-11-04
CVE-2014-3660 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2014-3660

Proof-of-concept code and exploit modules indexed by Sploitus