parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00041.html | mailing list |
http://xmlsoft.org/news.html | release notes vendor advisory |
https://usn.ubuntu.com/3739-1/ | vendor advisory |
https://github.com/GNOME/libxml2/commit/899a5d9f0ed13b8e32449a08a361e0de127dd961 | third party advisory patch |
https://bugzilla.gnome.org/show_bug.cgi?id=759579 | permissions required |
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E | mailing list |
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E | mailing list |
https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html | mailing list |