Cryptographic issues in expat - CVE-2012-6702

 

Cryptographic issues in expat - CVE-2012-6702

Published: June 16, 2016 / Updated: August 3, 2020


Vulnerability identifier: #VU33052
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6702
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.


Affected software

expat
Gentoo Linux
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
expat (Alpine package)
expat
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
NetWorker Management Console

How to mitigate CVE-2012-6702

Install update from vendor's website.

expat - update to 2.2.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
expat (Alpine package) - update to 2.2.0-r0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
expat - addressed in versions 2.1.1-2.fc22, 2.1.1-2.fc23, 2.1.1-2.fc24
NetWorker Management Console - update to 19.12.0.1

External References

Related Security Bulletins