libxml2: Missing validation for external entities in xmlParsePEReference
Published Feb 19, 2018
9.8
CRITICALCVSS 3.1
EPSS 2.59%
Description
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
Affected products
No data.
Configuration 2
- 7.0
- 8.0
- 9.0
Configuration 3
No data.
Red Hat Enterprise Linux 5
libxml2
Will not fix
Red Hat Enterprise Linux 6
libxml2
Will not fix
Red Hat Enterprise Linux 7
libxml2
Will not fix
Red Hat Enterprise Linux 8
libxml2
Not affected
Red Hat Enterprise Linux 8
mingw-libxml2
Affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Will not fix
Red Hat JBoss Core Services
libxml2
Affected
Red Hat JBoss Web Server 3
libxml2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libxml2 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libxml2 | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libxml2 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | libxml2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-libxml2 | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Will not fix | n/a |
| Red Hat JBoss Core Services | libxml2 | Affected | n/a |
| Red Hat JBoss Web Server 3 | libxml2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Dec 3, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.59% (0.02591) | 84.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.69% (0.02694) | 83.90th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.53% (0.00529) | 77.26th | v3 (v2023.03.01) |
| May 25, 2024 | 0.53% (0.00529) | 76.98th | v3 (v2023.03.01) |
| May 3, 2024 | 0.75% (0.00749) | 80.85th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.75% (0.00749) | 78.78th | v3 (v2023.03.01) |
| Jul 13, 2023 | 1.34% (0.01345) | 84.28th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.25% (0.02248) | 87.78th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Oct 19, 2022 | 1.18% (0.01183) | 60.79th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.18% (0.01183) | 35.15th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.78% (0.00775) | 20.98th | v1 |
| Jan 6, 2022 | 0.78% (0.00775) | 20.41th | v1 |
| Sep 1, 2021 | 0.78% (0.00775) | 49.48th | v1 |
| Apr 14, 2021 | 0.78% (0.00775) | 0.00th | v1 |
References (11)
- http://www.securityfocus.com/bid/98877 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038623 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-7375 Vendor Advisory
- https://android.googlesource.com/platform/external/libxml2/+/308396a55280f69ad4112d4f9892f4cbeff042aa x_refsource_CONFIRMPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1462203 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://git.gnome.org/browse/libxml2/commit/?id=90ccb58242866b0ba3edbef8fe44214a101c2b3e x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7375
- https://security.gentoo.org/glsa/201711-01 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://source.android.com/security/bulletin/2017-06-01 x_refsource_CONFIRMPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-7375
- https://www.debian.org/security/2017/dsa-3952 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.