CVE-2009-2625
published 2009-08-06CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20…
PriorityP434medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
30.38%
98.0th percentile
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.64 | 2.0.64 |
| apache | http_server | >= 2.2.0 < 2.2.17 | 2.2.17 |
| apache | xerces2_java | — | — |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | audacity | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cadaver | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cmake | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | coin3 | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | gdcm | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | ghostscript | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CMake vulnerabilities
vendor_ubuntu·2010-04-15·CVSS 5.0
CVE-2009-3560 [MEDIUM] CMake vulnerabilities
Title: CMake vulnerabilities
Summary: CMake vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for CMake.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: In general, a standard system upgrade
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2010-02-18·CVSS 5.0
CVE-2009-3560 [MEDIUM] XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: XML-RPC for C and C++ vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Inst
Ubuntu
PyXML vulnerabilities
vendor_ubuntu·2010-01-26·CVSS 5.0
CVE-2009-3560 [MEDIUM] PyXML vulnerabilities
Title: PyXML vulnerabilities
Summary: PyXML vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for PyXML.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you ne
Ubuntu
Python 2.4 vulnerabilities
vendor_ubuntu·2010-01-22·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.4 vulnerabilities
Title: Python 2.4 vulnerabilities
Summary: Python 2.4 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.4.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Python 2.5 vulnerabilities
vendor_ubuntu·2010-01-21·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.5 vulnerabilities
Title: Python 2.5 vulnerabilities
Summary: Python 2.5 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.5.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2010-01-20·CVSS 5.0
CVE-2009-2625 [MEDIUM] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat vulnerabilities
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.
Red Hat
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
vendor_redhat·2009-12-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 7) - Not affected
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-08-11·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
It was discovered that JAR bundles would appear signed if only one element
was signed. If a user were tricked into running a malicious Java applet, a
remote attacker could exploit this to gain access to private information and
potentially run untrusted code. (CVE-2009-1896)
It was discovered that certain variables could leak information. If a
user were tricked into running a malicious Java applet, a remote attacker
could exploit this to gain access to private information and potentially
run untrusted cod
Red Hat
JDK: XML parsing Denial-Of-Service (6845701)
vendor_redhat·2009-08-05·CVSS 5.0
CVE-2009-2625 [MEDIUM] JDK: XML parsing Denial-Of-Service (6845701)
JDK: XML parsing Denial-Of-Service (6845701)
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Previously, a denial-of-service flaw was found in Java which allowed the creation of an inifinte loop in XML headers that would consume all CPU resources. This issue was patched and Java is no longer vulnerable to a denial-of-service flaw due to the initiation of an infinte loop by means of XML headers.
Red Hat
expat: buffer over-read and crash on XML with malformed UTF-8 sequences
vendor_redhat·2009-01-17·CVSS 5.0
CVE-2009-3720 [MEDIUM] expat: buffer over-read and crash on XML with malformed UTF-8 sequences
expat: buffer over-read and crash on XML with malformed UTF-8 sequences
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Not affected
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 6) - Not affected
Package: python (Red Hat Enterprise Linux 6) - Not affected
Package: PyXML (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2009-2625: libxerces2-java - XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment ...
vendor_debian·2009·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625: libxerces2-java - XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment ...
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Scope: local
bookworm: resolved (fixed in 2.9.1-4.1)
bullseye: resolved (fixed in 2.9.1-4.1)
forky: resolved (fixed in 2.9.1-4.1)
sid: resolved (fixed in 2.9.1-4.1)
trixie: resolved (fixed in 2.9.1-4.1)
Debian
CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ...
vendor_debian·2009·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ...
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
Debian
CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
vendor_debian·2009·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
GHSA
GHSA-pj3x-74qr-vrr4: The updatePosition function in lib/xmltok_impl
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3720 [MEDIUM] GHSA-pj3x-74qr-vrr4: The updatePosition function in lib/xmltok_impl
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
GHSA
GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] CWE-119 GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
GHSA
Denial of service in Apache Xerces2
ghsa·2020-06-15
CVE-2009-2625 [MEDIUM] Denial of service in Apache Xerces2
Denial of service in Apache Xerces2
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
OSV
Denial of service in Apache Xerces2
osv·2020-06-15
CVE-2009-2625 [MEDIUM] Denial of service in Apache Xerces2
Denial of service in Apache Xerces2
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
OSV
CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
osv·2009-12-04·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
OSV
CVE-2009-3720: The updatePosition function in lib/xmltok_impl
osv·2009-11-03·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: The updatePosition function in lib/xmltok_impl
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
OSV
CVE-2009-2625: XMLScanner
osv·2009-08-06·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625: XMLScanner
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-14]
bugzilla·2011-11-04·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-14]
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-14]
fedora-14 tracking bug for centerim: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
According to http://www.centerim.org/index.php/Main_Page, centerim 4.22.10 fixes this flaw. Current EPEL6 and >=F15 have this version already, so only F14 and EPEL5 are vulnerable.
---
This message is a notice that Fedora 14 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 14. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
o
Bugzilla
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
bugzilla·2011-11-04·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
epel-5 tracking bug for centerim: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
According to http://www.centerim.org/index.php/Main_Page, centerim 4.22.10 fixes this flaw. Current EPEL6 and >=F15 have this version already, so only F14 and EPEL5 are vulnerable.
---
Hi Lubo,
Have you had a chance to review this BZ? If I can be of assistance feel free to let me know what you need done. Thanks.
JT
---
Fedora EPEL 5 changed to end-of-life (EOL) status on 2017-03-31. Fedora EPEL 5
is no longer maintained, which means that it will not receive
Bugzilla
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-all]
bugzilla·2011-03-25·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-all]
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=512921
Please note: this issue affects multipl
Bugzilla
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
bugzilla·2009-11-05·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1 allows context-dependent attackers to cause a denial of service (application crash)
via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Discussion:
Upstream patch (needs further testing):
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
---
expat-2.0.1-8.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc12
---
expat-2.0.1-8.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc11
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
bugzilla·2009-10-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
Peter Valchev discovered a flaw in the way expat handled malformed UTF-8 sequences when processing XML files. Incorrect UTF-8 sequenced could cause expat to fail to properly detect end of input and continue reading behind the end of input buffer. This results in a crash once reading reaches unmapped memory.
Non-public upstream bug report:
http://sourceforge.net/tracker/?func=detail&aid=1990430&group_id=10127&atid=110127
Contents of the report leaked via expat-bugs mailing list posts:
http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html
Upstream patch:
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15
References:
http://bugs.debian.org/cgi-bin/bugrep
Bugzilla
CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
bugzilla·2009-07-21·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
A denial of service flaw was found in the way the JRE processes XML. A
remote attacker could use this flaw to supply crafted XML that would lead
to a denial of service.
http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1199 https://rhn.redhat.com/errata/RHSA-2009-1199.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1200 https://rhn.redhat.com/errata/RHSA-2009-1200.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2009:1201 htt
http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1537.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37300http://secunia.com/advisories/37460http://secunia.com/advisories/37671http://secunia.com/advisories/37754http://secunia.com/advisories/38231http://secunia.com/advisories/38342http://secunia.com/advisories/43300http://secunia.com/advisories/50549http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-272209-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021506.1-1http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=572055&r2=787352&pathrev=787353&diff_format=hhttp://www.cert.fi/en/reports/2009/vulnerability2009085.htmlhttp://www.codenomicon.com/labs/xml/http://www.debian.org/security/2010/dsa-1984http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.mandriva.com/security/advisories?name=MDVSA-2011:108http://www.networkworld.com/columnists/2009/080509-xml-flaw.htmlhttp://www.openwall.com/lists/oss-security/2009/09/06/1http://www.openwall.com/lists/oss-security/2009/10/22/9http://www.openwall.com/lists/oss-security/2009/10/23/6http://www.openwall.com/lists/oss-security/2009/10/26/3http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1615.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0858.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/35958http://www.securitytracker.com/id?1022680http://www.ubuntu.com/usn/USN-890-1http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://www.us-cert.gov/cas/techalerts/TA10-012A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/2543http://www.vupen.com/english/advisories/2009/3316http://www.vupen.com/english/advisories/2011/0359https://bugzilla.redhat.com/show_bug.cgi?id=512921https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8520https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9356https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1636.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1637.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1649.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1650.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1537.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37300http://secunia.com/advisories/37460http://secunia.com/advisories/37671http://secunia.com/advisories/37754http://secunia.com/advisories/38231http://secunia.com/advisories/38342http://secunia.com/advisories/43300http://secunia.com/advisories/50549http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-272209-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021506.1-1http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=572055&r2=787352&pathrev=787353&diff_format=hhttp://www.cert.fi/en/reports/2009/vulnerability2009085.htmlhttp://www.codenomicon.com/labs/xml/http://www.debian.org/security/2010/dsa-1984http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.mandriva.com/security/advisories?name=MDVSA-2011:108http://www.networkworld.com/columnists/2009/080509-xml-flaw.htmlhttp://www.openwall.com/lists/oss-security/2009/09/06/1http://www.openwall.com/lists/oss-security/2009/10/22/9http://www.openwall.com/lists/oss-security/2009/10/23/6http://www.openwall.com/lists/oss-security/2009/10/26/3http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html
+ 26 more references
2009-08-06
Published