Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3560

Опубликовано: 02 дек. 2009
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xmlrpc-cWill not fix
Red Hat Enterprise Linux 6compat-expat1Not affected
Red Hat Enterprise Linux 6expatNot affected
Red Hat Enterprise Linux 7expatNot affected
Red Hat Enterprise Linux 3expatFixedRHSA-2009:162507.12.2009
Red Hat Enterprise Linux 4expatFixedRHSA-2009:162507.12.2009
Red Hat Enterprise Linux 5expatFixedRHSA-2009:162507.12.2009
Red Hat JBoss Enterprise Application Platform 6.4FixedRHSA-2017:323916.11.2017
Red Hat JBoss Web Server 1.0FixedRHSA-2011:089622.06.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=533174expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences

EPSS

Процентиль: 89%
0.04481
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.

nvd
больше 15 лет назад

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.

debian
больше 15 лет назад

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, a ...

github
около 3 лет назад

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 89%
0.04481
Низкий

5 Medium

CVSS2