cbcvebase.
CVE-2012-6702
published 2016-06-16

CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat…

medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleitunes
appleitunes_12.6_for_windows
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianexpat< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
debianlibxmltok< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
libexpat_projectlibexpat< 2.2.02.2.0

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM