CVE-2009-3560
expat - regression fix
EPSS 24.3%
描述
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
如何修補 CVE-2009-3560
要修補 CVE-2009-3560,請將受影響套件升級到下列已修補版本。
- Debian/audacity—升級至 1.3.2-1 或更新版本
- Debian/cadaver—未列出修補版本
- —升級至 2.6.0-6 或更新版本
- —升級至 4.0.0~CMake~6f54f1602475+ds1-1 或更新版本
- —升級至 2.0.1-6 或更新版本
- —升級至 1.95.8-3.4+etch2 或更新版本
- —升級至 1.95.8-3.4+etch3 或更新版本
- —升級至 2.0.14-2 或更新版本
- —升級至 8.71~dfsg-2 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 0.10.0-1 或更新版本
- —升級至 3.6.2-1 或更新版本
- —升級至 1.3.6p1-1 或更新版本
- —升級至 2.10.0-1 或更新版本
- —升級至 0.8.3~20080525-1 或更新版本
- —升級至 1.3.5+dfsg-15 或更新版本
- —升級至 2.1.8-4 或更新版本
- —升級至 1.06.27-1.1 或更新版本
CVE-2009-3560 正在被利用嗎?
中等 — EPSS 為 24.3%,可持續追蹤但非最高優先。
受影響套件(19)
- from 0, < 1.3.2-1
- from 0
- from 0, < 2.6.0-6
- from 0, < 4.0.0~CMake~6f54f1602475+ds1-1
- from 0, < 2.0.1-6
- from 0, < 1.95.8-3.4+etch2
- from 0, < 1.95.8-3.4+etch3
- from 0, < 2.0.14-2
- from 0, < 8.71~dfsg-2
- from 0
- from 0
- from 0, < 0.10.0-1
- from 0, < 3.6.2-1