CVE-2009-3720
expat - denial of service
EPSS 27.9%
描述
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
如何修補 CVE-2009-3720
要修補 CVE-2009-3720,請將受影響套件升級到下列已修補版本。
- Debian/audacity—升級至 1.3.2-1 或更新版本
- Debian/cadaver—未列出修補版本
- —升級至 2.6.0-6 或更新版本
- —升級至 4.0.0~CMake~6f54f1602475+ds1-1 或更新版本
- —升級至 2.0.1-5 或更新版本
- —升級至 1.95.8-3.4+etch1 或更新版本
- —升級至 2.0.14-2 或更新版本
- —升級至 8.71~dfsg-2 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 0.10.0-1 或更新版本
- —升級至 3.6.2-1 或更新版本
- —升級至 1.3.6p1-1 或更新版本
- —升級至 2.10.0-1 或更新版本
- —升級至 0.8.3~20080525-1 或更新版本
- —升級至 1.3.5+dfsg-15 或更新版本
- —升級至 2.1.8-4 或更新版本
- —升級至 1.06.27-1.1 或更新版本
- —升級至 1.6.5-1.2 或更新版本
CVE-2009-3720 正在被利用嗎?
中等 — EPSS 為 27.9%,可持續追蹤但非最高優先。
受影響套件(19)
- from 0, < 1.3.2-1
- from 0
- from 0, < 2.6.0-6
- from 0, < 4.0.0~CMake~6f54f1602475+ds1-1
- from 0, < 2.0.1-5
- from 0, < 1.95.8-3.4+etch1
- from 0, < 2.0.14-2
- from 0, < 8.71~dfsg-2
- from 0
- from 0
- from 0, < 0.10.0-1
- from 0, < 3.6.2-1
- from 0, < 1.3.6p1-1