Vulnerability Description
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmltwig | Xml-Twig For Perl | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00033.html
- http://www.openwall.com/lists/oss-security/2016/11/04/2Third Party Advisory
- http://www.securityfocus.com/bid/94219Third Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00033.html
- http://www.openwall.com/lists/oss-security/2016/11/04/2Third Party Advisory
- http://www.securityfocus.com/bid/94219Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-9180?
CVE-2016-9180 is a vulnerability with a CVSS score of 9.1 (CRITICAL). perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's s...
How severe is CVE-2016-9180?
CVE-2016-9180 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-9180?
Check the references section above for vendor advisories and patch information. Affected products include: Xmltwig Xml-Twig For Perl.