Security Advisories (2)
CVE-2015-3451 (2015-04-23)

The _clone function does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

CVE-2017-10672 (2015-04-23)

Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.

NAME

XML::LibXML::DocumentFragment - DOM L2 Implementation of a Document Fragment

DESCRIPTION

This class is a helper class as described in the DOM Level 2 Specification. It is implamented as a node without name. All adding, inserting or replacing functions are aware about document fragments now.

As well all unbound nodes (all nodes that does not belong to any document subtree) are implicit member of document fragments. =back

AUTHOR

Matt Sergeant, Christian Glahn

SEE ALSO

XML::LibXML, XML::LibXML::Node, XML::LibXML::Element, XML::LibXML::Document, XML::LibXML::Text, XML::LibXML::Comment, XML::LibXML::CDATASection

VERSION

1.49