CVE-2017-9233
🟡 Monitoruj
Wykorzystanie podatności w libexpat pozwala na zablokowanie parsera w nieskończonej pętli.
CVSS
7.5
EPSS
8.7%
Exploit
poc
Vendor
python
Opis źródłowy (NVD)
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
exploit xxe
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 8.7% |
| Opublikowano (NVD) | 2017-07-25 20:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:06 UTC |
Referencje
- http://www.debian.org/security/2017/dsa-3898 ([email protected]) [Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2017/06/17/7 ([email protected]) [Mailing List, VDB Entry]
- http://www.securityfocus.com/bid/99276 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1039427 ([email protected]) [Third Party Advisory, VDB Entry]
- https://github.com/libexpat/libexpat/blob/master/expat/Changes ([email protected]) [Release Notes, Third Party Advisory]
- https://libexpat.github.io/doc/cve-2017-9233/ ([email protected]) [Exploit, Technical Description, Vendor Advisory]
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E ([email protected])
- https://support.apple.com/HT208112 ([email protected]) [Third Party Advisory]
- https://support.apple.com/HT208113 ([email protected]) [Third Party Advisory]
- https://support.apple.com/HT208115 ([email protected]) [Third Party Advisory]
- https://support.apple.com/HT208144 ([email protected]) [Third Party Advisory]
- https://support.f5.com/csp/article/K03244804 ([email protected]) [Third Party Advisory]