Candidate: CVE-2017-1000190 PublicDate: 2017-11-17 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000190 https://github.com/ngallagher/simplexml/issues/18 Description: SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. Ubuntu-Description: Notes: msalvatore> As of 11/09/2018, there is a comment on github recommending updating to "2.7.3". This may be the fix version. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H [9.1 CRITICAL] Patches_simple-xml: upstream_simple-xml: needed precise/esm_simple-xml: DNE trusty_simple-xml: ignored (reached end-of-life) trusty/esm_simple-xml: DNE (trusty was needed) xenial_simple-xml: ignored (end of standard support, was needed) zesty_simple-xml: ignored (reached end-of-life) artful_simple-xml: ignored (reached end-of-life) bionic_simple-xml: needed cosmic_simple-xml: ignored (reached end-of-life) disco_simple-xml: ignored (reached end-of-life) eoan_simple-xml: not-affected (2.7.1-3) focal_simple-xml: not-affected (2.7.1-3) groovy_simple-xml: not-affected (2.7.1-3) hirsute_simple-xml: not-affected (2.7.1-3) impish_simple-xml: not-affected (2.7.1-3) jammy_simple-xml: not-affected (2.7.1-3) devel_simple-xml: not-affected (2.7.1-3)