Описание
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | xmlrpc-c | Not affected | ||
Red Hat Enterprise Linux 6 | compat-expat1 | Not affected | ||
Red Hat Enterprise Linux 6 | expat | Not affected | ||
Red Hat Enterprise Linux 6 | python | Not affected | ||
Red Hat Enterprise Linux 6 | PyXML | Not affected | ||
Red Hat Enterprise Linux 7 | expat | Not affected | ||
Red Hat Enterprise Linux 3 | 4Suite | Fixed | RHSA-2009:1572 | 10.11.2009 |
Red Hat Enterprise Linux 3 | expat | Fixed | RHSA-2009:1625 | 07.12.2009 |
Red Hat Enterprise Linux 4 | 4Suite | Fixed | RHSA-2009:1572 | 10.11.2009 |
Red Hat Enterprise Linux 4 | expat | Fixed | RHSA-2009:1625 | 07.12.2009 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ...
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
EPSS
5 Medium
CVSS2