DEBIAN-CVE-2009-3720

Advisory lineage Upstream: 1 Downstream: 2
Upstream
Published: 03 Nov 2009, 16:30
Last modified:07 May 2026, 12:00

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Nov 2009, 16:30
Published
Vulnerability first disclosed
07 May 2026, 12:00
Last Modified
Vulnerability information updated

Description

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

Affected Systems

  • debianaudacity

    < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1 | < 1.3.2-1

  • debiancadaver

    all | all | all | all

  • debiancmake

    < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6 | < 2.6.0-6

  • debiancoin3

    all | all | all | all | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1 | < 4.0.0~CMake~6f54f1602475+ds1-1

  • debianexpat

    < 2.0.1-5 | < 2.0.1-5 | < 2.0.1-5 | < 2.0.1-5

  • debiangdcm

    < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2 | < 2.0.14-2

  • debianghostscript

    < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2 | < 8.71~dfsg-2

  • debianlibxmltok

    all | all

  • debianmatanza

    all | all | all | all

  • debianmcabber

    < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1 | < 0.10.0-1

  • debianparaview

    < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1 | < 3.6.2-1

  • debianpoco

    < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1 | < 1.3.6p1-1

  • debiansimgear

    < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1 | < 2.10.0-1

  • debiantdom

    < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1 | < 0.8.3~20080525-1

  • debiantla

    < 1.3.5+dfsg-15 | < 1.3.5+dfsg-15

  • debianudunits

    < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4 | < 2.1.8-4

  • debianxmlrpc-c

    < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1 | < 1.06.27-1.1

  • debianxotcl

    < 1.6.5-1.2 | < 1.6.5-1.2 | < 1.6.5-1.2 | < 1.6.5-1.2

References (1)