Modified
Published: 03 Jul 2012, 19:00
Last modified:06 Aug 2024, 18:38

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.17% LOW
0% probability -0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2012, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 18:38
Last Modified
Vulnerability information updated

Description

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.17% Percentile: 37%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    8.04 | 10.04 | 11.04 | 11.10 | 12.04

  • debiandebian_linux

    6.0 | 7.0

  • libexpat_projectlibexpat

    < 2.1.0

  • UnknownSolaris

    11.3

  • pythonpython

    ≥ 2.6.0, < 2.6.8 | ≥ 2.7.0, < 2.7.3 | ≥ 3.1.0, < 3.1.5 | ≥ 3.2.0, < 3.2.3

  • redhatenterprise_linux_desktop

    5.0 | 6.0

  • redhatenterprise_linux_eus

    6.2

  • redhatenterprise_linux_server

    5.0 | 6.0

  • redhatenterprise_linux_server_aus

    6.2

  • redhatenterprise_linux_workstation

    5.0 | 6.0

  • redhatstorage

    2.0

References (22)