~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
https://ubuntu.com/security/notices/USN-5427-1 | third party advisory vendor advisory |
https://www.cve.org/CVERecord?id=CVE-2022-28652 | third party advisory issue tracking |