PT-2012-1121 · Expat+3 · Expat+3

Kurt Seifried

·

Published

2012-07-03

·

Updated

2024-06-15

·

CVE-2012-1147

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions expat versions prior to 2.1.0
Description The issue concerns multiple vulnerabilities in the expat package that can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, in versions before 2.1.0, context-dependent attackers can cause a denial of service by consuming file descriptors via a large number of crafted XML files, as seen in the readfilemap.c file.
Recommendations For expat versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of XML files from untrusted sources to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-45093
BDU:2015-09649
CVE-2012-1147
OPENSUSE-SU-2024:10077-1

Affected Products

Debian
Suse
Expat
Itunes