REDHAT-BUG-1437311
Published Mar 30, 2017
·Updated
xmlsec is vulnerable to XML External Entity Expansion via libxml2 (see CVE-2016-9318). A workaround is in progress on the upstream bug report. Upstream bug: https://github.com/lsh123/xmlsec/issues/43
Affected Software
2 affected components
xmlsec xmlsec
libxml2 libxml2
Event History
Mar 30, 2017
Data Sourced
via Red Hat·03:41 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1437311?
REDHAT-BUG-1437311 is classified as a moderate vulnerability due to potential XML External Entity Expansion.
2
How do I fix REDHAT-BUG-1437311?
To fix REDHAT-BUG-1437311, you should apply any available patches for xmlsec and libxml2 once they are released.
3
What software is affected by REDHAT-BUG-1437311?
REDHAT-BUG-1437311 affects xmlsec and libxml2 software components.
4
What type of vulnerability is REDHAT-BUG-1437311?
REDHAT-BUG-1437311 is an XML External Entity Expansion vulnerability.
5
Is there a workaround for REDHAT-BUG-1437311?
Yes, a workaround is currently being developed as noted in the upstream bug report for REDHAT-BUG-1437311.