CVE-2016-9318: Canonical Ubuntu Linux
Medium severity, CVSS 5.5. EPSS: 2.9% chance of exploitation in the next 30 days.
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
- Xmlsoft LIBXML2: up to and including 2.9.4
Published 2016-11-16. Last modified 2026-06-17.