CVE-2009-3720Project Libexpat vulnerability

25 documents9 sources
Severity
5.0MEDIUMNVD
EPSS
1.2%
top 21.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateMay 2

Description

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDapache/http_server2.0.352.0.64+1
Debianmcabber/mcabber< 0.10.0-1+3
Debiansimgear/simgear< 2.10.0-1+3
Debianpocoproject/poco< 1.3.6p1-1+3

🔴Vulnerability Details

3
GHSA
GHSA-pj3x-74qr-vrr4: The updatePosition function in lib/xmltok_impl2022-05-02
OSV
CVE-2009-3720: The updatePosition function in lib/xmltok_impl2009-11-03
CVEList
CVE-2009-3720: The updatePosition function in lib/xmltok_impl2009-11-03

📋Vendor Advisories

11
Apple
CVE-2009-3720: iTunes 12.62017-03-21
Apple
CVE-2009-3720: iTunes 12.6 for Windows2017-03-21
Ubuntu
CMake vulnerabilities2010-04-15
Ubuntu
XML-RPC for C and C++ vulnerabilities2010-02-18
Ubuntu
PyXML vulnerabilities2010-01-26

💬Community

10
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]2011-03-29
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]2011-03-29
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]2011-03-29
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [epel-all]2011-03-29
Bugzilla
CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences [fedora-all]2011-03-29
CVE-2009-3720 — Libexpat Project Libexpat vulnerability | cvebase