A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
{ "vanir_signatures": [ { "target": { "file": "testapi.c" }, "id": "CVE-2021-3541-1aa97e63", "deprecated": false, "digest": { "line_hashes": [ "61551077790304056876126381115245055965", "278846916215258117913027984776762678417", "335982757857177150834168525661853921922", "87840030754328165737181167332541198940", "61551077790304056876126381115245055965", "278846916215258117913027984776762678417", "105711474186756975709469310745455797308", "103706706750952072917010335478765316004", "227047217400973127911964602216150042388", "253258039250536385915162828640596572926", "335982757857177150834168525661853921922", "87840030754328165737181167332541198940", "227047217400973127911964602216150042388", "253258039250536385915162828640596572926", "105711474186756975709469310745455797308", "263486003320329746243870951465374401173", "112950646771093583388072220651695062566", "231864520689178078662381811343978537663", "213333773092754020127207462965134162165", "19008729915787537273927561381864711242", "112950646771093583388072220651695062566", "231864520689178078662381811343978537663", "213333773092754020127207462965134162165", "19008729915787537273927561381864711242", "273240550832595461615251408636344817319", "162912241845094166163791832543701405088", "671650474723048413359612334217206008", "22766956053755843453510076977580137201", "13167474649499926961065524423099785312", "83470413458974766405520199037916535562", "276402490468899750538561900822383734744", "333682037389609673181412300351361172030", "9499193487410093391036358074880903632", "30805303948970631633603096678317204355", "93889085830397632709481663916004609330", "229956981014592868447519071218013779439", "240624245583924818381392266620352655927", "223174899253645334504338538819361168413", "294476493037697202535040764027097131119", "129304591418198192271541858825325701656", "140204848231080657012011575632498051783", "75311632195512841680531928924350830586", "256053888072821081238103619703165798762", "235378452580802392739918607691411522119", "244992818881073020881304797438692585130", "66651940352215863530508914348900210359", "48019944339009281467628355593178272818", "106918772490863171659640772695582053951", "116925370429586760959130651896312835976", "148133004854708868535797103792350393744", "102183146399774788380381559441867815797", "308117370035021215489377534456228663968", "187339639605561687559806077174150854909", "130836858511549172127312257489846408951", "52797561731550596294797782502825671297", "313419538420946173683294680071732735569", "246138447249870484217065672110268629284" ], "threshold": 0.9 }, "source": "https://github.com/gnome/libxml2/commit/e1bcffea180d6cc0651757bb64284a763e0e2239", "signature_type": "Line", "signature_version": "v1" }, { "target": { "function": "test_xmlIO", "file": "testapi.c" }, "id": "CVE-2021-3541-4ad7707d", "deprecated": false, "digest": { "function_hash": "198329610838053062539893085088781189951", "length": 1155.0 }, "source": "https://github.com/gnome/libxml2/commit/e1bcffea180d6cc0651757bb64284a763e0e2239", "signature_type": "Function", "signature_version": "v1" } ] }