DEBIAN-CVE-2009-3560

Advisory lineage Upstream: 1 Downstream: 3
Published: 04 Dec 2009, 21:30
Last modified:07 May 2026, 12:00

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Dec 2009, 21:30
Published
Vulnerability first disclosed
07 May 2026, 12:00
Last Modified
Vulnerability information updated

Description

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.

Affected Systems

  • debianaudacity

    < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1

  • debiancadaver

    all | all | all | all

  • debiancmake

    < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6

  • debiancoin3

    all | all | all | all | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1

  • debianexpat

    < 2.0.1-6 | < 2.0.1-6 | < 2.0.1-6 | < 2.0.1-6

  • debiangdcm

    < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2

  • debianghostscript

    < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2

  • debianlibxmltok

    all | all

  • debianmatanza

    all | all | all | all

  • debianmcabber

    < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1

  • debianparaview

    < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1

  • debianpoco

    < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1

  • debiansimgear

    < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1

  • debiantdom

    < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1

  • debiantla

    < 1.3.5+dfsg-15 | < 1.3.5+dfsg-15

  • debianudunits

    < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4

  • debianxmlrpc-c

    < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1

References (1)