CVE-2012-1148

Aliases:DEBIAN-CVE-2012-1148
Modified
Published: 03 Jul 2012, 19:00
Last modified:06 Aug 2024, 18:45

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
3.56% LOW
4% probability +2.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2012, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 18:45
Last Modified
Vulnerability information updated

Description

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 3.56% Percentile: 89%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • applemac_os_x

    ≤ 10.11.1

  • debianexpat

    < 2.1.0~beta3-1 | < 2.1.0~beta3-1 | < 2.1.0~beta3-1 | < 2.1.0~beta3-1

  • debianlibxmltok

    all | all

  • debianxmlrpc-c

    < 1.16.33-3.2 | < 1.16.33-3.2 | < 1.16.33-3.2 | < 1.16.33-3.2

  • libexpat_projectlibexpat

    ≤ 2.0.1 | 1.95.1 | 1.95.2 | 1.95.4 | 1.95.5 | 1.95.6 | 1.95.7 | 1.95.8 | 2.0.0

References (19)