CVE-2013-0340

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
21/01/2014
Last modified:
11/04/2025

Description

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* 2.4.0 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.15 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.7.0 (including) 3.7.12 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.8.0 (including) 3.8.12 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.9.0 (including) 3.9.7 (excluding)
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 14.8 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 14.8 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 11.6 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 15.0 (excluding)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 8.0 (excluding)


References to Advisories, Solutions, and Tools