Input validation error in expat - CVE-2016-5300
Published: June 16, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32074
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5300
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows context-dependent attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (CPU consumption) via crafted identifiers in an XML document.
Affected software
expat
Gentoo Linux
Slackware Linux
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
expat (Alpine package)
expat
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
NetWorker Management Console
Gentoo Linux
Slackware Linux
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
expat (Alpine package)
expat
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
NetWorker Management Console
How to mitigate CVE-2016-5300
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
expat (Alpine package) - update to 2.2.0-r0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
expat - addressed in versions 2.1.1-2.fc22, 2.1.1-2.fc23, 2.1.1-2.fc24
NetWorker Management Console - update to 19.12.0.1
expat (Alpine package) - update to 2.2.0-r0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
expat - addressed in versions 2.1.1-2.fc22, 2.1.1-2.fc23, 2.1.1-2.fc24
NetWorker Management Console - update to 19.12.0.1
External References
- http://www.debian.org/security/2016/dsa-3597
- http://www.openwall.com/lists/oss-security/2016/06/04/4
- http://www.openwall.com/lists/oss-security/2016/06/04/5
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.securityfocus.com/bid/91159
- http://www.ubuntu.com/usn/USN-3010-1
- https://security.gentoo.org/glsa/201701-21
- https://source.android.com/security/bulletin/2016-11-01.html
- https://www.tenable.com/security/tns-2016-20
Related Security Bulletins
- Input validation error in libexpat expat
- Input validation error in expat (Alpine package)
- Gentoo update for Expat
- Slackware Linux update for python
- Multiple vulnerabilities in Dell ThinOS
- Fedora 24 update for expat
- Fedora 23 update for expat
- Fedora 22 update for expat
- Dell NetWorker Management Console update for third-party components