Resource management error in expat - CVE-2012-0876
Published: July 3, 2012 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
Affected software
Amazon Linux AMI
Gentoo Linux
Slackware Linux
expat (Alpine package)
HPE NonStop Virtual Tape Repository (VTR)
NetWorker Management Console
How to mitigate CVE-2012-0876
expat (Alpine package) - update to 2.1.0-r0
HPE NonStop Virtual Tape Repository (VTR) - update to T09644V01^AAK
NetWorker Management Console - update to 19.12.0.1
External References
- http://bugs.python.org/issue13703#msg151870
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html
- http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html
- http://mail.libexpat.org/pipermail/expat-discuss/2012-March/002768.html
- http://rhn.redhat.com/errata/RHSA-2012-0731.html
- http://rhn.redhat.com/errata/RHSA-2016-0062.html
- http://rhn.redhat.com/errata/RHSA-2016-2957.html
- http://secunia.com/advisories/49504
- http://secunia.com/advisories/51024
- http://secunia.com/advisories/51040
- http://sourceforge.net/projects/expat/files/expat/2.1.0/
- http://sourceforge.net/tracker/?func=detail&atid=110127&aid=3496608&group_id=10127
- http://www.debian.org/security/2012/dsa-2525
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:041
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.securityfocus.com/bid/52379
- http://www.ubuntu.com/usn/USN-1527-1
- http://www.ubuntu.com/usn/USN-1613-1
- http://www.ubuntu.com/usn/USN-1613-2
- https://support.apple.com/HT205637
- https://www.tenable.com/security/tns-2016-20
Related Security Bulletins
- Resource management error in libexpat expat
- Resource management error in expat (Alpine package)
- Amazon Linux AMI update for expat
- Gentoo update for Expat
- Slackware Linux update for python
- Multiple vulnerabilities in HPE NonStop Vrtual Tape Repository (VTR)
- Dell NetWorker Management Console update for third-party components