PT-2012-1120 · Expat+4 · Expat+4
Vincent Danen
·
Publicado
2012-06-13
·
Atualizado
2024-06-15
·
CVE-2012-0876
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
expat versions prior to 2.1.0
Description
The issue is related to the XML parser in expat, which computes hash values without restricting the ability to trigger hash collisions predictably. This allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value. The exploitation of this issue can lead to a disruption of protected information and can be performed remotely.
Recommendations
For expat versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of XML files with many identifiers with the same value to minimize the risk of exploitation.
Correção
DoS
Buffer Overflow
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Debian
Red Hat
Suse
Expat