CVE-2017-9233 is an XML External Entity (XXE) vulnerability in libexpat 2.2.0 and earlier, affecting various Debian and Python products that utilize the library. This flaw allows attackers to trigger an infinite loop in the XML parser by crafting a malformed external entity definition within an external DTD. With a CVSS score of 7.5 (High), the vulnerability presents a network-based attack vector with low complexity, leading to high availability impact (denial of service) without requiring user interaction or privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.0CPE matchmatch criteria | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.15CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.7CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.7CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.4CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.