CVE-2021-3541: Medium severity IBM Security Verify Access vulnerability
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
Other sources
GNOME libxml2 is vulnerable to a denial of service, caused by an exponential entity expansion attack which bypasses all existing protection mechanisms. A remote authenticated attacker could exploit this vulnerability to consume all available resources.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3541?
CVE-2021-3541 is a vulnerability found in libxml2 that allows for an exponential entity expansion attack, bypassing existing protection mechanisms and leading to denial of service.
What is the severity of CVE-2021-3541?
CVE-2021-3541 has a severity rating of 6.5, which is considered medium.
Which software is affected by CVE-2021-3541?
Software affected by CVE-2021-3541 includes jbcs-httpd24-apr-util, jbcs-httpd24-curl, jbcs-httpd24-httpd, jbcs-httpd24-nghttp2, jbcs-httpd24-openssl, jbcs-httpd24-openssl-chil, jbcs-httpd24-openssl-pkcs11, and libxml2.
How can I fix CVE-2021-3541?
To fix CVE-2021-3541, update your software to the recommended versions provided by the respective vendors.
Where can I find more information about CVE-2021-3541?
You can find more information about CVE-2021-3541 on the Red Hat Security Advisory and Bugzilla pages.