CVE-2009-3720

Aliases:DEBIAN-CVE-2009-3720
Modified
Published: 03 Nov 2009, 16:00
Last modified:07 Aug 2024, 06:38

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
27.92% HIGH
28% probability +26.76%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Nov 2009, 16:00
Published
Vulnerability first disclosed
07 Aug 2024, 06:38
Last Modified
Vulnerability information updated

Description

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 27.92% Percentile: 98%

Affected Systems

  • apachehttp_server

    ≥ 2.0.35, < 2.0.64 | ≥ 2.2.0, < 2.2.17

  • debianaudacity

    < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1

  • debiancadaver

    all | all | all | all

  • debiancmake

    < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6

  • debiancoin3

    < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1

  • debianexpat

    < 2.0.1-5 | < 2.0.1-5 | < 2.0.1-5 | < 2.0.1-5

  • debiangdcm

    < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2

  • debianghostscript

    < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2

  • debianlibxmltok

    all | all

  • debianmatanza

    all | all | all | all

  • debianmcabber

    < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1

  • debianparaview

    < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1

  • debianpoco

    < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1

  • debiansimgear

    < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1

  • debiantdom

    < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1

  • debiantla

    < 1.3.5+dfsg-15 | < 1.3.5+dfsg-15

  • debianudunits

    < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4

  • debianxmlrpc-c

    < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1

  • debianxotcl

    < 1.6.5-1.2 | < 1.6.5-1.2 | < 1.6.5-1.2 | < 1.6.5-1.2

  • libexpat_projectlibexpat

    2.0.1

References (94)