CVE-2009-3560
published 2009-12-04CVE-2009-3560: The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
24.31%
97.6th percentile
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.64 | 2.0.64 |
| apache | http_server | >= 2.2.0 < 2.2.17 | 2.2.17 |
| apple | itunes | — | — |
| apple | itunes_12.6_for_windows | — | — |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| debian | audacity | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cadaver | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cmake | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | coin3 | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | expat | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | gdcm | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | ghostscript | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | libxmltok | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | matanza | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | mcabber | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | paraview | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | poco | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | simgear | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] CWE-119 GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
OSV
CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
osv·2009-12-04·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Apple
CVE-2009-3560: iTunes 12.6
vendor_apple·2017-03-21·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2009-3560
Component: CVE-2009-3560
Apple
CVE-2009-3560: iTunes 12.6 for Windows
vendor_apple·2017-03-21·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: iTunes 12.6 for Windows
Apple Security Update: About the security content of iTunes 12.6 for Windows
Product: iTunes 12.6 for Windows
CVE: CVE-2009-3560
Component: CVE-2009-3560
Ubuntu
CMake vulnerabilities
vendor_ubuntu·2010-04-15·CVSS 5.0
CVE-2009-3560 [MEDIUM] CMake vulnerabilities
Title: CMake vulnerabilities
Summary: CMake vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for CMake.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: In general, a standard system upgrade
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2010-02-18·CVSS 5.0
CVE-2009-3560 [MEDIUM] XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: XML-RPC for C and C++ vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Inst
Ubuntu
PyXML vulnerabilities
vendor_ubuntu·2010-01-26·CVSS 5.0
CVE-2009-3560 [MEDIUM] PyXML vulnerabilities
Title: PyXML vulnerabilities
Summary: PyXML vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for PyXML.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you ne
Ubuntu
Python 2.4 vulnerabilities
vendor_ubuntu·2010-01-22·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.4 vulnerabilities
Title: Python 2.4 vulnerabilities
Summary: Python 2.4 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.4.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Python 2.5 vulnerabilities
vendor_ubuntu·2010-01-21·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.5 vulnerabilities
Title: Python 2.5 vulnerabilities
Summary: Python 2.5 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.5.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2010-01-20·CVSS 5.0
CVE-2009-2625 [MEDIUM] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat vulnerabilities
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.
Red Hat
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
vendor_redhat·2009-12-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
vendor_debian·2009·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Update to Expat 2.2.1
bugzilla·2017-06-18·CVSS 4.3
[MEDIUM] Update to Expat 2.2.1
Update to Expat 2.2.1
Update expat files that live in: parser/expat/lib/
For list of fixed CVEs see:
http://www.openwall.com/lists/oss-security/2017/06/17/7
Discussion:
This fixes some integer overflows, a double free and more. So marking s-s for now.
---
FWIW I've explicitly avoided updating to the latest expat versions as they've tend to introduce more CVE's than they fix. We keep a much trimmed down (and modified) version of 2.0.0 in tree, it would be interesting to see what overlap there is and maybe just cherry-pick changes that are relevant to us.
---
I've started looking over the differences. I'll attach some patches with some no-brainers and then we can decide on the rest.
---
From the release notes:
CVE-2017-9233 External entity infinite loop DoS
Probably affects us, I
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: thi
Bugzilla
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
bugzilla·2009-11-05·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1 allows context-dependent attackers to cause a denial of service (application crash)
via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Discussion:
Upstream patch (needs further testing):
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
---
expat-2.0.1-8.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc12
---
expat-2.0.1-8.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc11
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
bugzilla·2009-10-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
Peter Valchev discovered a flaw in the way expat handled malformed UTF-8 sequences when processing XML files. Incorrect UTF-8 sequenced could cause expat to fail to properly detect end of input and continue reading behind the end of input buffer. This results in a crash once reading reaches unmapped memory.
Non-public upstream bug report:
http://sourceforge.net/tracker/?func=detail&aid=1990430&group_id=10127&atid=110127
Contents of the report leaked via expat-bugs mailing list posts:
http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html
Upstream patch:
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15
References:
http://bugs.debian.org/cgi-bin/bugrep
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://mail.python.org/pipermail/expat-bugs/2009-November/002846.htmlhttp://marc.info/?l=bugtraq&m=130168502603566&w=2http://secunia.com/advisories/37537http://secunia.com/advisories/38231http://secunia.com/advisories/38794http://secunia.com/advisories/38832http://secunia.com/advisories/38834http://secunia.com/advisories/39478http://secunia.com/advisories/41701http://secunia.com/advisories/43300http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1http://www.debian.org/security/2009/dsa-1953http://www.mandriva.com/security/advisories?name=MDVSA-2009:316http://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/bid/37203http://www.securitytracker.com/id?1023278http://www.ubuntu.com/usn/USN-890-1http://www.ubuntu.com/usn/USN-890-6http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/0896http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2011/0359https://bugzilla.redhat.com/show_bug.cgi?id=533174https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10613https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6883https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00394.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.htmlhttp://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://mail.python.org/pipermail/expat-bugs/2009-November/002846.htmlhttp://marc.info/?l=bugtraq&m=130168502603566&w=2http://secunia.com/advisories/37537http://secunia.com/advisories/38231http://secunia.com/advisories/38794http://secunia.com/advisories/38832http://secunia.com/advisories/38834http://secunia.com/advisories/39478http://secunia.com/advisories/41701http://secunia.com/advisories/43300http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1http://www.debian.org/security/2009/dsa-1953http://www.mandriva.com/security/advisories?name=MDVSA-2009:316http://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/bid/37203http://www.securitytracker.com/id?1023278http://www.ubuntu.com/usn/USN-890-1http://www.ubuntu.com/usn/USN-890-6http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/0896http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2011/0359https://bugzilla.redhat.com/show_bug.cgi?id=533174https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
+ 16 more references
2009-12-04
Published