libxml2: CPU consumption DoS and other effects when performing string substitutions during external entities expansion
Published Jan 21, 2014
6.8
MEDIUMCVSS 2.0
EPSS 3.61%
Description
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
Affected products
No data.
Configuration 1
- ≤ 2.9.1
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.8.7
- 1.8.9
- 1.8.10
- 1.8.13
- 1.8.14
- 1.8.16
- 2.0.0
- 2.1.0
- 2.1.1
- 2.2.0
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 2.2.10
- 2.2.11
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.3.7
- 2.3.8
- 2.3.9
- 2.3.10
- 2.3.11
- 2.3.12
- 2.3.13
- 2.3.14
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.4.8
- 2.4.9
- 2.4.10
- 2.4.11
- 2.4.12
- 2.4.13
- 2.4.14
- 2.4.15
- 2.4.16
- 2.4.17
- 2.4.18
- 2.4.19
- 2.4.20
- 2.4.21
- 2.4.22
- 2.4.23
- 2.4.24
- 2.4.25
- 2.4.26
- 2.4.27
- 2.4.28
- 2.4.29
- 2.4.30
- 2.5.0
- 2.5.4
- 2.5.7
- 2.5.8
- 2.5.10
- 2.5.11
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.6.5
- 2.6.6
- 2.6.7
- 2.6.8
- 2.6.9
- 2.6.11
- 2.6.12
- 2.6.13
- 2.6.14
- 2.6.16
- 2.6.17
- 2.6.18
- 2.6.20
- 2.6.21
- 2.6.22
- 2.6.23
- 2.6.24
- 2.6.25
- 2.6.26
- 2.6.27
- 2.6.28
- 2.6.29
- 2.6.30
- 2.6.31
- 2.6.32
- 2.7.0
- 2.7.1
- 2.7.2
- 2.7.3
- 2.7.4
- 2.7.5
- 2.7.6
- 2.7.7
- 2.7.8
- 2.8.0
- 2.9.0
- 2.9.0
Configuration 2
- 10.04
- 12.04
- 12.10
- 13.04
- 6.0
- 7.0
- 10
No data.
Red Hat Enterprise Linux 5
libxml2
Will not fix
Red Hat Enterprise Linux 6
libxml2
Will not fix
Red Hat Enterprise Linux 6
mingw32-libxml2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libxml2 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libxml2 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | mingw32-libxml2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.61% (0.03609) | 89.13th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.42% (0.04420) | 90.07th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.73% (0.01725) | 80.73th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.17% (0.04175) | 80.83th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.73% (0.01725) | 81.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.62% (0.01624) | 88.00th | v3 (v2023.03.01) |
| Jan 20, 2024 | 1.86% (0.01860) | 87.08th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.71% (0.01712) | 86.35th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.59% (0.00592) | 74.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.41% (0.03407) | 84.65th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.41% (0.03407) | 83.10th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.41% (0.03407) | 66.20th | v2 (v2022.01.01) |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00002.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2013/02/21/24 mailing-listx_refsource_MLIST
- http://openwall.com/lists/oss-security/2013/02/22/3 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2013/q4/182 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2013/q4/184 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2013/q4/188 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/52662 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54172 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/55568 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2013/dsa-2652 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2013/04/12/6 mailing-listx_refsource_MLIST
- http://www.ubuntu.com/usn/USN-1904-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-1904-2 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-0339 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=915149 x_refsource_MISCIssue Tracking
- https://git.gnome.org/browse/libxml2/commit/?id=4629ee02ac649c27f9c0cf98ba017c6b5526070f x_refsource_MISCExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-0339
- https://www.cve.org/CVERecord?id=CVE-2013-0339
Change history (0)
No recorded changes yet.