Description
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-990-1 | expat security update |
Debian DSA |
DSA-3898-1 | expat security update |
EUVD |
EUVD-2017-18171 | XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD. |
Ubuntu USN |
USN-3356-1 | Expat vulnerability |
Ubuntu USN |
USN-3356-2 | Expat vulnerability |
Ubuntu USN |
USN-4825-1 | Coin3D vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:02:43.627Z
Reserved: 2017-05-26T00:00:00.000Z
Link: CVE-2017-9233
No data.
Status : Modified
Published: 2017-07-25T20:29:00.220
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-9233
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN