xml-conduit unbounded entity expansion
A vulnerability was found in xml-conduit. It has been
classified as problematic. Affected is an unknown function of the file
xml-conduit/src/Text/XML/Stream/Parse.hs
of the component
DOCTYPE Entity Expansion Handler. The manipulation leads to infinite
loop. It is possible to launch the attack remotely. Upgrading to version
1.9.1.0 is able to address this issue. The name of the patch is
4be1021791dcdee8b164d239433a2043dc0939ea
. It is recommended
to upgrade the affected component.
Info
- Published
- July 18, 2023
- Modified
- July 18, 2023
- CAPECs
- < none >
- CWEs
- 776
- Keywords
- xml, dos, historical
- Aliases
- CVE-2021-4249, VDB-216204
- Related
- < none >
- References
- [FIX] https://github.com/snoyberg/xml/pull/161
- [FIX] https://github.com/snoyberg/xml/commit/4be1021791dcdee8b164d239433a2043dc0939ea
Affected
xml-conduit
- CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Versions
>=0.5.0 && <1.9.1.0
- Declarations
- < none >