CVE-2009-3720
EPSS 1.6%expat - denial of service
發布日:2009/11/3修改日:2026/5/7
描述
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
受影響套件(19)
- Debian/audacityfrom 0, < 1.3.2-1
- Debian/cadaverfrom 0
- Debian/cmakefrom 0, < 2.6.0-6
- Debian/coin3from 0, < 4.0.0~CMake~6f54f1602475+ds1-1
- Debian/expatfrom 0, < 2.0.1-5
- Debian/expatfrom 0, < 1.95.8-3.4+etch1
- Debian/gdcmfrom 0, < 2.0.14-2
- Debian/ghostscriptfrom 0, < 8.71~dfsg-2
- Debian/libxmltokfrom 0
- Debian/matanzafrom 0
- Debian/mcabberfrom 0, < 0.10.0-1
- Debian/paraviewfrom 0, < 3.6.2-1
- Debian/pocofrom 0, < 1.3.6p1-1
- Debian/simgearfrom 0, < 2.10.0-1
- Debian/tdomfrom 0, < 0.8.3~20080525-1
- Debian/tlafrom 0, < 1.3.5+dfsg-15
- Debian/udunitsfrom 0, < 2.1.8-4
- Debian/xmlrpc-cfrom 0, < 1.06.27-1.1
- Debian/xotclfrom 0, < 1.6.5-1.2