CVE-2009-3720
published 2009-11-03CVE-2009-3720: The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
27.92%
97.9th percentile
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.64 | 2.0.64 |
| apache | http_server | >= 2.2.0 < 2.2.17 | 2.2.17 |
| apple | itunes | — | — |
| apple | itunes_12.6_for_windows | — | — |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-2 | 8.71~dfsg-2 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| audacityteam | audacity | >= 0 < 1.3.2-1 | 1.3.2-1 |
| debian | audacity | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cadaver | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | cmake | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | coin3 | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | expat | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | gdcm | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | ghostscript | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | libxmltok | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | matanza | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | mcabber | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | paraview | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | poco | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
| debian | simgear | < audacity 1.3.2-1 (bookworm) | audacity 1.3.2-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pj3x-74qr-vrr4: The updatePosition function in lib/xmltok_impl
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3720 [MEDIUM] GHSA-pj3x-74qr-vrr4: The updatePosition function in lib/xmltok_impl
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
GHSA
GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] CWE-119 GHSA-pcgv-8c5g-4m8p: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
OSV
CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
osv·2009-12-04·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: The big2_toUtf8 function in lib/xmltok
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
OSV
CVE-2009-3720: The updatePosition function in lib/xmltok_impl
osv·2009-11-03·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: The updatePosition function in lib/xmltok_impl
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Apple
CVE-2009-3720: iTunes 12.6
vendor_apple·2017-03-21·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2009-3720
Component: CVE-2009-3720
Apple
CVE-2009-3720: iTunes 12.6 for Windows
vendor_apple·2017-03-21·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: iTunes 12.6 for Windows
Apple Security Update: About the security content of iTunes 12.6 for Windows
Product: iTunes 12.6 for Windows
CVE: CVE-2009-3720
Component: CVE-2009-3720
Ubuntu
CMake vulnerabilities
vendor_ubuntu·2010-04-15·CVSS 5.0
CVE-2009-3560 [MEDIUM] CMake vulnerabilities
Title: CMake vulnerabilities
Summary: CMake vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for CMake.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: In general, a standard system upgrade
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2010-02-18·CVSS 5.0
CVE-2009-3560 [MEDIUM] XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: XML-RPC for C and C++ vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Inst
Ubuntu
PyXML vulnerabilities
vendor_ubuntu·2010-01-26·CVSS 5.0
CVE-2009-3560 [MEDIUM] PyXML vulnerabilities
Title: PyXML vulnerabilities
Summary: PyXML vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for PyXML.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you ne
Ubuntu
Python 2.4 vulnerabilities
vendor_ubuntu·2010-01-22·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.4 vulnerabilities
Title: Python 2.4 vulnerabilities
Summary: Python 2.4 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.4.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Python 2.5 vulnerabilities
vendor_ubuntu·2010-01-21·CVSS 5.0
CVE-2009-3560 [MEDIUM] Python 2.5 vulnerabilities
Title: Python 2.5 vulnerabilities
Summary: Python 2.5 vulnerabilities
USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for the PyExpat module in Python 2.5.
Original advisory details:
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: A
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2010-01-20·CVSS 5.0
CVE-2009-2625 [MEDIUM] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat vulnerabilities
Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)
It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)
Instructions: After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.
Red Hat
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
vendor_redhat·2009-12-02·CVSS 5.0
CVE-2009-3560 [MEDIUM] expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 7) - Not affected
Red Hat
expat: buffer over-read and crash on XML with malformed UTF-8 sequences
vendor_redhat·2009-01-17·CVSS 5.0
CVE-2009-3720 [MEDIUM] expat: buffer over-read and crash on XML with malformed UTF-8 sequences
expat: buffer over-read and crash on XML with malformed UTF-8 sequences
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Not affected
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 6) - Not affected
Package: python (Red Hat Enterprise Linux 6) - Not affected
Package: PyXML (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ...
vendor_debian·2009·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ...
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
Debian
CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
vendor_debian·2009·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ...
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Update to Expat 2.2.1
bugzilla·2017-06-18·CVSS 4.3
[MEDIUM] Update to Expat 2.2.1
Update to Expat 2.2.1
Update expat files that live in: parser/expat/lib/
For list of fixed CVEs see:
http://www.openwall.com/lists/oss-security/2017/06/17/7
Discussion:
This fixes some integer overflows, a double free and more. So marking s-s for now.
---
FWIW I've explicitly avoided updating to the latest expat versions as they've tend to introduce more CVE's than they fix. We keep a much trimmed down (and modified) version of 2.0.0 in tree, it would be interesting to see what overlap there is and maybe just cherry-pick changes that are relevant to us.
---
I've started looking over the differences. I'll attach some patches with some no-brainers and then we can decide on the rest.
---
From the release notes:
CVE-2017-9233 External entity infinite loop DoS
Probably affects us, I
Bugzilla
CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
bugzilla·2013-07-09·CVSS 5.0
CVE-2012-1148 [MEDIUM] CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mult
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: thi
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: thi
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: thi
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [epel-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [epel-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: this
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
bugzilla·2011-03-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=531697
Please note: thi
Bugzilla
udunits2 contains an embedded copy of expat, prone to CVE-2009-3720
bugzilla·2010-11-13·CVSS 5.0
CVE-2009-3720 [MEDIUM] udunits2 contains an embedded copy of expat, prone to CVE-2009-3720
udunits2 contains an embedded copy of expat, prone to CVE-2009-3720
Description of problem:
udinits2 contains an old embedded version of the expat xml parsing library. Code
inspection shows this embedded copy is vulnerable to CVE-2009-3720 and possibly
other issues.
Version-Release number of selected component (if applicable):
Version: 2.1.11
Release: 1.dc13
Additional info:
The CVE https://bugzilla.redhat.com/show_bug.cgi?id=531697
Ideally, the best solution is to link in the system expat library and not use
the embedded copy. This would help prevent these types of security issues from
reoccuring.
I have marked this issue as a security issue due to the fact that a CVE was
assigned to expat. I have not investigated how this vulnerability would be
triggered by udunits2.
Discussion
Bugzilla
libnodeupdown-backend-ganglia contains an embedded copy of expat, prone to CVE-2009-3720
bugzilla·2010-11-13·CVSS 5.0
CVE-2009-3720 [MEDIUM] libnodeupdown-backend-ganglia contains an embedded copy of expat, prone to CVE-2009-3720
libnodeupdown-backend-ganglia contains an embedded copy of expat, prone to CVE-2009-3720
Description of problem:
This library contains an old embedded version of the expat xml parsing library. Code inspection shows this embedded copy is vulnerable to CVE-2009-3720 and possibly other issues.
Version-Release number of selected component (if applicable):
Name: libnodeupdown-backend-ganglia
Version: 1.9
Release: 5.fc13
Additional info:
The cve https://bugzilla.redhat.com/show_bug.cgi?id=531697
Ideally, the best solution is to link in the system expat library and not use
the embedded copy. This would help prevent these types of security issues from
reoccuring.
I have marked this issue as a security issue due to the fact that a CVE was
assigned to expat. I have not investigated how this
Bugzilla
libtlen contains an embedded copy of expat, prone to CVE-2009-3720
bugzilla·2010-11-12·CVSS 5.0
CVE-2009-3720 [MEDIUM] libtlen contains an embedded copy of expat, prone to CVE-2009-3720
libtlen contains an embedded copy of expat, prone to CVE-2009-3720
Description of problem:
libtlen contains an old embedded version of the expat xml parsing library. Code inspection shows this embedded copy is vulnerable to CVE-2009-3720 and possibly other issues.
Version-Release number of selected component (if applicable):
Version: 0
Release: 0.9.20060309.fc12
Additional info:
Ideally, the best solution is to link in the system expat library and not use the embedded copy. This would help prevent these types of security issues from reoccuring.
I have marked this issue as a security issue due to the fact that a CVE was assigned to expat. I have not investigated how this vulnerability would be triggered by libtlen.
Discussion:
Should be fixed in 0-0.10.20060309 across the board:
h
Bugzilla
Centerim: Embeds libmsn, libyahoo2, libgadu
bugzilla·2009-12-07
[LOW] Centerim: Embeds libmsn, libyahoo2, libgadu
Centerim: Embeds libmsn, libyahoo2, libgadu
The latest version of centerim package, as shipped with Fedora 12
(centerim-4.22.8-1.fc12) embeds own copies of multiple libraries
(libmsn, libyahoo2, libgadu) which are already available as separate
Fedora packages.
Please consider to switch from using own, embedded library copies
to use of system ones, provided by relevant packages.
Additional info:
.../BUILD/centerim-4.22.8/Makefile.in contains following:
119 DIST_SUBDIRS = connwrap kkstrtext kksystr kkconsui libicq2000 libmsn \
120 libyahoo2 firetalk libgadu libjabber intl po misc share src
From those, libmsn, libyahoo2 and libgadu are already available as
separate Fedora packages.
Discussion:
This message is a reminder that Fedora 12 is nearing its end of life.
Approximately 30 (thir
Bugzilla
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
bugzilla·2009-11-05·CVSS 5.0
CVE-2009-3560 [MEDIUM] CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1 allows context-dependent attackers to cause a denial of service (application crash)
via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Discussion:
Upstream patch (needs further testing):
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
---
expat-2.0.1-8.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc12
---
expat-2.0.1-8.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/expat-2.0.1-8.fc11
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
bugzilla·2009-10-29·CVSS 5.0
CVE-2009-3720 [MEDIUM] CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences
Peter Valchev discovered a flaw in the way expat handled malformed UTF-8 sequences when processing XML files. Incorrect UTF-8 sequenced could cause expat to fail to properly detect end of input and continue reading behind the end of input buffer. This results in a crash once reading reaches unmapped memory.
Non-public upstream bug report:
http://sourceforge.net/tracker/?func=detail&aid=1990430&group_id=10127&atid=110127
Contents of the report leaked via expat-bugs mailing list posts:
http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html
Upstream patch:
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15
References:
http://bugs.debian.org/cgi-bin/bugrep
Bugzilla
CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
bugzilla·2009-07-21·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
A denial of service flaw was found in the way the JRE processes XML. A
remote attacker could use this flaw to supply crafted XML that would lead
to a denial of service.
http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1199 https://rhn.redhat.com/errata/RHSA-2009-1199.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1200 https://rhn.redhat.com/errata/RHSA-2009-1200.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2009:1201 htt
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patchhttp://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=loghttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051228.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051405.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051442.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://mail.python.org/pipermail/expat-bugs/2009-January/002781.htmlhttp://marc.info/?l=bugtraq&m=130168502603566&w=2http://secunia.com/advisories/37324http://secunia.com/advisories/37537http://secunia.com/advisories/37925http://secunia.com/advisories/38050http://secunia.com/advisories/38231http://secunia.com/advisories/38794http://secunia.com/advisories/38832http://secunia.com/advisories/38834http://secunia.com/advisories/39478http://secunia.com/advisories/41701http://secunia.com/advisories/42326http://secunia.com/advisories/42338http://secunia.com/advisories/43300http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026http://sourceforge.net/tracker/index.php?func=detail&aid=1990430&group_id=10127&atid=110127http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1http://svn.python.org/view?view=rev&revision=74429http://www.mandriva.com/security/advisories?name=MDVSA-2009:211http://www.mandriva.com/security/advisories?name=MDVSA-2009:212http://www.mandriva.com/security/advisories?name=MDVSA-2009:215http://www.mandriva.com/security/advisories?name=MDVSA-2009:216http://www.mandriva.com/security/advisories?name=MDVSA-2009:217http://www.mandriva.com/security/advisories?name=MDVSA-2009:218http://www.mandriva.com/security/advisories?name=MDVSA-2009:219http://www.mandriva.com/security/advisories?name=MDVSA-2009:220http://www.openwall.com/lists/oss-security/2009/08/21/2http://www.openwall.com/lists/oss-security/2009/08/26/3http://www.openwall.com/lists/oss-security/2009/08/26/4http://www.openwall.com/lists/oss-security/2009/08/27/6http://www.openwall.com/lists/oss-security/2009/09/06/1http://www.openwall.com/lists/oss-security/2009/10/22/5http://www.openwall.com/lists/oss-security/2009/10/22/9http://www.openwall.com/lists/oss-security/2009/10/23/2http://www.openwall.com/lists/oss-security/2009/10/23/6http://www.openwall.com/lists/oss-security/2009/10/26/3http://www.openwall.com/lists/oss-security/2009/10/28/3http://www.redhat.com/support/errata/RHSA-2010-0002.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securitytracker.com/id?1023160http://www.ubuntu.com/usn/USN-890-1http://www.ubuntu.com/usn/USN-890-6http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/0896http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/3035http://www.vupen.com/english/advisories/2010/3053http://www.vupen.com/english/advisories/2010/3061http://www.vupen.com/english/advisories/2011/0359https://bugs.gentoo.org/show_bug.cgi?id=280615https://bugzilla.redhat.com/show_bug.cgi?id=531697https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11019https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12719https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7112https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01274.htmlhttp://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patchhttp://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=loghttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051228.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051405.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/051442.html
+ 86 more references
2009-11-03
Published