Name | CVE-2016-9180 |
Description | perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 842893 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
libxml-twig-perl (PTS) | bullseye | 1:3.52-1 | fixed |
| bookworm | 1:3.52-2 | fixed |
| sid, trixie | 1:3.52-3 | fixed |
The information below is based on the following data on fixed versions.
Notes
[stretch] - libxml-twig-perl <no-dsa> (Minor issue; can be fixed via point release)
[jessie] - libxml-twig-perl <no-dsa> (Minor issue; can be fixed via point release)
[wheezy] - libxml-twig-perl <no-dsa> (Minor issue, new flag would require changes to applications too, not worth the effort)
https://rt.cpan.org/Public/Bug/Display.html?id=118097
https://bugzilla.redhat.com/show_bug.cgi?id=1379553
https://www.openwall.com/lists/oss-security/2016/11/02/1
Release 3.50 adds a no_xxe flag which will fail to parse files with external entities.
2016-12-13: The corresponding changes is not in the public git repository yet: https://github.com/mirod/xmltwig/commits/master