DEBIAN-CVE-2015-3451

Source
https://security-tracker.debian.org/tracker/CVE-2015-3451
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-3451.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2015-3451
Upstream
Downstream
Published
2015-05-12T19:59:21Z
Modified
2026-09-09T06:47:27Z
Summary
[none]
Details

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

References

Affected packages

Debian:12 / libxml-libxml-perl

Package

Name
libxml-libxml-perl
Purl
pkg:deb/debian/libxml-libxml-perl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0116+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-3451.json"

Debian:13 / libxml-libxml-perl

Package

Name
libxml-libxml-perl
Purl
pkg:deb/debian/libxml-libxml-perl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0116+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-3451.json"

Debian:14 / libxml-libxml-perl

Package

Name
libxml-libxml-perl
Purl
pkg:deb/debian/libxml-libxml-perl?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0116+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-3451.json"