PT-2009-1105 · Expat+5 · Expat+5

Published

2009-01-17

·

Updated

2024-06-15

·

CVE-2009-3720

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Expat versions prior to 2.1.0 beta3
Description The issue is related to multiple vulnerabilities in the expat package, which can lead to a denial of service. This can be exploited remotely. Specifically, the updatePosition function in lib/xmltok impl.c allows context-dependent attackers to cause an application crash via an XML document with crafted UTF-8 sequences that trigger a buffer over-read. A buffer over-read flaw was also found in the bundled expat library, which can cause a crash if an attacker can get Apache to parse an untrusted XML document.
Recommendations For versions prior to 2.1.0 beta3, update to version 2.1.0 beta3 or later to resolve the issue. As a temporary workaround, consider restricting access to the updatePosition function in lib/xmltok impl.c until a patch is available. Additionally, avoid parsing untrusted XML documents to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43945
AZL-44685
BDU:2015-09649
CVE-2009-3720
DSA-1921-1
DSA-1977-1
HPSBUX02645
OPENSUSE-SU-2024:10077-1
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:10568-1
RHSA-2009:1572
RHSA-2009:1625
RHSA-2009_1572
RHSA-2009_1625
RHSA-2010:0002
RHSA-2010_0002
RHSA-2011:0491
RHSA-2011:0492
RHSA-2011_0491
RHSA-2011_0492
USN-890-1
USN-890-2
USN-890-3
USN-890-4
USN-890-5
USN-890-6

Affected Products

Apache Http Server
Debian
Expat
Hp-Ux
Red Hat
Itunes