Security Advisories (2)
CVE-2015-3451 (2015-04-23)

The _clone function does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

CVE-2017-10672 (2015-04-23)

Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.

NAME

XML::LibXML::DOM - XML::LibXML DOM implementation

DESCRIPTION

XML::LibXML implements a native DOM so the parsed structures are accessable from the perl layer. The current implementation offers an alternative interface to many DOM functions in addition to the specified functions. These functions will be removed in future versions or renamed to perl style names.

XML::LibXML's DOM implementation tries to follow the various DOM specs although not all interfaces are implemented yet. Also there some efford is taken to also to follow the XPath DOM extensions. There are many functions that are specified for DOM and already present in XML::LibXML's DOM API, but still not documented.

Although XML::LibXML provides the more important interfaces to node structures, there are not all node types implemented (yet). The more common functions are provided by XML::LibXML::Node, so it should be possible to access most parts of the document. Since XML::LibXML wraps only the document structure provided by libxml2, XML::LibXML::Node will not work properly with nodes found in a DTD, since they are not nodes in context of libxml2. Besides that XML::LibXML's DOM Api should provide a more perlish interface to the DOM structure libxml2 generates. =back

AUTHOR

Matt Sergeant, Christian Glahn

VERSION

1.49