{"id":"CVE-2017-7375","details":"A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).","modified":"2026-08-07T11:48:00.905808050Z","published":"2018-02-19T19:29:00.703Z","related":["SUSE-SU-2017:1813-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING"},{"vendor_product":"google:android","cpes":["cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*","cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*","cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*","cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*","cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*","cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.4.4"},{"last_affected":"4.4.4"},{"introduced":"5.0.2"},{"last_affected":"5.0.2"},{"introduced":"5.1.1"},{"last_affected":"5.1.1"},{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"6.0.1"},{"last_affected":"6.0.1"},{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"7.1.1"},{"last_affected":"7.1.1"},{"introduced":"7.1.2"},{"last_affected":"7.1.2"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98877"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1038623"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201711-01"},{"type":"ADVISORY","url":"https://www.debian.org/security/2017/dsa-3952"},{"type":"FIX","url":"https://android.googlesource.com/platform/external/libxml2/+/308396a55280f69ad4112d4f9892f4cbeff042aa"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1462203"},{"type":"FIX","url":"https://git.gnome.org/browse/libxml2/commit/?id=90ccb58242866b0ba3edbef8fe44214a101c2b3e"},{"type":"FIX","url":"https://source.android.com/security/bulletin/2017-06-01"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libxml2","events":[{"introduced":"0"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"introduced":"a1dca81df7c352cd9a14ab678750b1623f8f8ed7"},{"last_affected":"8effcb578e0590cc01bbcab0f9dccefc6bdbcdbd"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*","cpe:2.3:a:xmlsoft:libxml2:2.9.4:rc1:*:*:*:*:*:*","cpe:2.3:a:xmlsoft:libxml2:2.9.4:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.9.4"},{"introduced":"2.9.4-rc1"},{"last_affected":"2.9.4-rc1"},{"introduced":"2.9.4-rc2"},{"last_affected":"2.9.4-rc2"}]}}],"versions":["2.9.4-rc1","2.9.4-rc2","v2.9.4","CVE-2016-3627","CVE-2016-1833","CVE-2016-1835","CVE-2016-1837","CVE-2016-1836","CVE-2016-1839","CVE-2016-1838","CVE-2016-1840","CVE-2016-4449","CVE-2016-4483","CVE-2016-1834","CVE-2016-3705","v2.9.4-rc2","v2.9.4-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7375.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"0"},{"last_affected":"bdec2183f34b37ee89ae1d330c6ad2bb4d76605f"},{"introduced":"a1dca81df7c352cd9a14ab678750b1623f8f8ed7"},{"last_affected":"8effcb578e0590cc01bbcab0f9dccefc6bdbcdbd"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*","cpe:2.3:a:xmlsoft:libxml2:2.9.4:rc1:*:*:*:*:*:*","cpe:2.3:a:xmlsoft:libxml2:2.9.4:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.9.4"},{"introduced":"2.9.4-rc1"},{"last_affected":"2.9.4-rc1"},{"introduced":"2.9.4-rc2"},{"last_affected":"2.9.4-rc2"}]}}],"versions":["2.9.4-rc1","2.9.4-rc2","v2.9.4","CVE-2016-3627","CVE-2016-1833","CVE-2016-1835","CVE-2016-1837","CVE-2016-1836","CVE-2016-1839","CVE-2016-1838","CVE-2016-1840","CVE-2016-4449","CVE-2016-4483","CVE-2016-1834","CVE-2016-3705","v2.9.4-rc2","v2.9.4-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7375.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}