CVE-2012-0876
published 2012-07-03CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.72%
92.2th percentile
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.1.1-3 (bookworm) | expat 2.1.1-3 (bookworm) |
| debian | expat | < expat 2.1.0~beta3-1 (bookworm) | expat 2.1.0~beta3-1 (bookworm) |
| debian | libxmltok | < expat 2.1.1-3 (bookworm) | expat 2.1.1-3 (bookworm) |
| debian | libxmltok | < expat 2.1.0~beta3-1 (bookworm) | expat 2.1.0~beta3-1 (bookworm) |
| debian | xmlrpc-c | < expat 2.1.0~beta3-1 (bookworm) | expat 2.1.0~beta3-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| libexpat_project | libexpat | < 2.2.0 | 2.2.0 |
| libexpat_project | libexpat | < 2.1.0 | 2.1.0 |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8w9-7fww-v592: The XML parser (xmlparse
ghsa_unreviewed·2022-05-13
CVE-2012-0876 [MEDIUM] CWE-400 GHSA-q8w9-7fww-v592: The XML parser (xmlparse
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
GHSA
GHSA-59r7-7hc4-v4rf: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2016-5300 [MEDIUM] GHSA-59r7-7hc4-v4rf: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
OSV
CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service
osv·2016-06-16·CVSS 4.3
CVE-2016-5300 [MEDIUM] CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
OSV
CVE-2012-0876: The XML parser (xmlparse
osv·2012-07-03·CVSS 4.3
CVE-2012-0876 [MEDIUM] CVE-2012-0876: The XML parser (xmlparse
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
Red Hat
expat: Little entropy used for hash initialization
vendor_redhat·2016-06-04·CVSS 4.3
CVE-2016-5300 [MEDIUM] CWE-331 expat: Little entropy used for hash initialization
expat: Little entropy used for hash initialization
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
Package: expat (Red Hat Directory Server 8) - Under investigation
Package: expat (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Will not fix
Package: xulrunner (Red Hat Enterprise Linux 5) - Not affected
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Pack
Debian
CVE-2016-5300: expat - The XML parser in Expat does not use sufficient entropy for hash initialization,...
vendor_debian·2016·CVSS 4.3
CVE-2016-5300 [MEDIUM] CVE-2016-5300: expat - The XML parser in Expat does not use sufficient entropy for hash initialization,...
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
Scope: local
bookworm: resolved (fixed in 2.1.1-3)
bullseye: resolved (fixed in 2.1.1-3)
forky: resolved (fixed in 2.1.1-3)
sid: resolved (fixed in 2.1.1-3)
trixie: resolved (fixed in 2.1.1-3)
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
Ubuntu
Python 2.5 vulnerabilities
vendor_ubuntu·2012-10-17·CVSS 6.9
CVE-2008-5983 [MEDIUM] Python 2.5 vulnerabilities
Title: Python 2.5 vulnerabilities
Summary: Several security issues were fixed in Python 2.5.
It was discovered that Python would prepend an empty string to sys.path
under certain circumstances. A local attacker with write access to the
current working directory could exploit this to execute arbitrary code.
(CVE-2008-5983)
It was discovered that the audioop module did not correctly perform input
validation. If a user or automatated system were tricked into opening a
crafted audio file, an attacker could cause a denial of service via
application crash. (CVE-2010-1634, CVE-2010-2089)
Giampaolo Rodola discovered several race conditions in the smtpd module.
A remote attacker could exploit this to cause a denial of service via
daemon outage. (CVE-2010-3493)
It was discovered that the CGIHTT
Ubuntu
Python 2.4 vulnerabilities
vendor_ubuntu·2012-10-17·CVSS 6.9
CVE-2010-2089 [MEDIUM] Python 2.4 vulnerabilities
Title: Python 2.4 vulnerabilities
Summary: Several security issues were fixed in Python 2.4.
USN-1613-1 fixed vulnerabilities in Python 2.5. This update provides the
corresponding updates for Python 2.4.
Original advisory details:
It was discovered that Python would prepend an empty string to sys.path
under certain circumstances. A local attacker with write access to the
current working directory could exploit this to execute arbitrary code.
(CVE-2008-5983)
It was discovered that the audioop module did not correctly perform input
validation. If a user or automatated system were tricked into opening a
crafted audio file, an attacker could cause a denial of service via
application crash. (CVE-2010-1634, CVE-2010-2089)
Giampaolo Rodola discovered several race conditions in the smtpd mod
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2012-09-10·CVSS 4.3
CVE-2012-0876 [MEDIUM] XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: XML-RPC for C and C++ could be made to cause a denial of service by consuming
excessive CPU and memory resources.
USN-1527-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++. Both issues described in the
original advisory affected XML-RPC for C and C++ in Ubuntu 10.04 LTS, 11.04,
11.10 and 12.04 LTS.
Original advisory details:
It was discovered that Expat computed hash values without restricting the
ability to trigger hash collisions predictably. If a user or application
linked against Expat were tricked into opening a crafted XML file, an attacker
could cause a denial of service by consuming excessive CPU resources.
(CVE-2012-0876)
Tim Boddy discovered that Expat did not prop
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 4.3
CVE-2012-0876 [MEDIUM] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to cause a denial of service by consuming excessive CPU
and memory resources.
It was discovered that Expat computed hash values without restricting the
ability to trigger hash collisions predictably. If a user or application linked
against Expat were tricked into opening a crafted XML file, an attacker could
cause a denial of service by consuming excessive CPU resources. (CVE-2012-0876)
Tim Boddy discovered that Expat did not properly handle memory reallocation
when processing XML files. If a user or application linked against Expat were
tricked into opening a crafted XML file, an attacker could cause a denial of
service by consuming excessive memory resources. This issue only affected
Ubuntu 8.04 LTS, 10.04 LTS, 11.04 and 11.10.
Red Hat
expat: hash table collisions CPU usage DoS
vendor_redhat·2012-03-03·CVSS 4.3
CVE-2012-0876 [MEDIUM] CWE-407 expat: hash table collisions CPU usage DoS
expat: hash table collisions CPU usage DoS
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
A denial of service flaw was found in the implementation of hash arrays in Expat. An attacker could use this flaw to make an application using Expat consume an excessive amount of CPU time by providing a specially crafted XML file that triggers multiple hash function collisions. To mitigate this issue, randomization has been added to the hash function to reduce the chance of an attacker successfully causing intentional collisions.
Package: expat (Red Hat Direc
Debian
CVE-2012-0876: expat - The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without r...
vendor_debian·2012·CVSS 4.3
CVE-2012-0876 [MEDIUM] CVE-2012-0876: expat - The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without r...
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
Scope: local
bookworm: resolved (fixed in 2.1.0~beta3-1)
bullseye: resolved (fixed in 2.1.0~beta3-1)
forky: resolved (fixed in 2.1.0~beta3-1)
sid: resolved (fixed in 2.1.0~beta3-1)
trixie: resolved (fixed in 2.1.0~beta3-1)
Apple
CVE-2012-0876: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
vendor_apple·CVSS 4.3
CVE-2012-0876 [MEDIUM] CVE-2012-0876: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Product: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
CVE: CVE-2012-0876
Component: CVE-ID
Impact: Parsing a maliciously crafted XML document may lead to disclosure of user information
Description: A memory corruption issue existed in the parsing of XML files. This issue was addressed through improved memory handling.
No detection rules found.
No public exploits indexed.
Bugzilla
Update to Expat 2.2.1
bugzilla·2017-06-18·CVSS 4.3
[MEDIUM] Update to Expat 2.2.1
Update to Expat 2.2.1
Update expat files that live in: parser/expat/lib/
For list of fixed CVEs see:
http://www.openwall.com/lists/oss-security/2017/06/17/7
Discussion:
This fixes some integer overflows, a double free and more. So marking s-s for now.
---
FWIW I've explicitly avoided updating to the latest expat versions as they've tend to introduce more CVE's than they fix. We keep a much trimmed down (and modified) version of 2.0.0 in tree, it would be interesting to see what overlap there is and maybe just cherry-pick changes that are relevant to us.
---
I've started looking over the differences. I'll attach some patches with some no-brainers and then we can decide on the rest.
---
From the release notes:
CVE-2017-9233 External entity infinite loop DoS
Probably affects us, I
Bugzilla
CVE-2016-5300 expat: Little entropy used for hash initialization
bugzilla·2016-06-06·CVSS 4.3
CVE-2016-5300 [MEDIUM] CVE-2016-5300 expat: Little entropy used for hash initialization
CVE-2016-5300 expat: Little entropy used for hash initialization
It was found that original fix for CVE-2012-0876 used too little entropy for the hash intilization.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/473
Discussion:
Created compat-expat1 tracking bugs for this issue:
Affects: fedora-all [bug 1343087]
---
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 1343086]
---
Created mingw-expat tracking bugs for this issue:
Affects: fedora-all [bug 1343088]
Affects: epel-7 [bug 1343090]
---
Created expat21 tracking bugs for this issue:
Affects: epel-all [bug 1343089]
---
Created attachment 1165210
Proposed upstream patch
Bugzilla
CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
bugzilla·2013-07-09·CVSS 5.0
CVE-2012-1148 [MEDIUM] CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
CVE-2012-1148 CVE-2012-0876 compat-expat1 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mult
Bugzilla
CVE-2012-0876 expat: hash table collisions CPU usage DoS
bugzilla·2012-02-01·CVSS 4.3
CVE-2012-0876 [MEDIUM] CVE-2012-0876 expat: hash table collisions CPU usage DoS
CVE-2012-0876 expat: hash table collisions CPU usage DoS
Similar to the denial of service flaw present in various programming languages' hash function usage, a flaw was found in expat:
A specially-crafted set of keys could trigger hash function collisions, which
degrade dictionary performance by changing hash table operations complexity
from an expected/average O(1) to the worst case O(n). Reporters were able to
find colliding strings efficiently using meet in the middle attack.
This problem is similar to the issue that was previously reported for and fixed
in e.g. perl:
http://www.cs.rice.edu/~scrosby/hash/CrosbyWallach_UsenixSec2003.pdf
Discussion:
This is sort of public due to discussion on the embedded expat in python:
http://bugs.python.org/issue13703#msg151870
---
Created att
http://bugs.python.org/issue13703#msg151870http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://mail.libexpat.org/pipermail/expat-discuss/2012-March/002768.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0731.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0062.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://secunia.com/advisories/49504http://secunia.com/advisories/51024http://secunia.com/advisories/51040http://sourceforge.net/projects/expat/files/expat/2.1.0/http://sourceforge.net/tracker/?func=detail&atid=110127&aid=3496608&group_id=10127http://www.debian.org/security/2012/dsa-2525http://www.mandriva.com/security/advisories?name=MDVSA-2012:041http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/52379http://www.ubuntu.com/usn/USN-1527-1http://www.ubuntu.com/usn/USN-1613-1http://www.ubuntu.com/usn/USN-1613-2https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://support.apple.com/HT205637https://www.tenable.com/security/tns-2016-20http://bugs.python.org/issue13703#msg151870http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://mail.libexpat.org/pipermail/expat-discuss/2012-March/002768.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0731.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0062.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://secunia.com/advisories/49504http://secunia.com/advisories/51024http://secunia.com/advisories/51040http://sourceforge.net/projects/expat/files/expat/2.1.0/http://sourceforge.net/tracker/?func=detail&atid=110127&aid=3496608&group_id=10127http://www.debian.org/security/2012/dsa-2525http://www.mandriva.com/security/advisories?name=MDVSA-2012:041http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/52379http://www.ubuntu.com/usn/USN-1527-1http://www.ubuntu.com/usn/USN-1613-1http://www.ubuntu.com/usn/USN-1613-2https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://support.apple.com/HT205637https://www.tenable.com/security/tns-2016-20
2012-07-03
Published