Resource exhaustion in expat - CVE-2013-0340

 

Resource exhaustion in expat - CVE-2013-0340

Published: January 21, 2014 / Updated: October 11, 2021


Vulnerability identifier: #VU42119
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0340
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attackers to cause a denial of service attack.

The vulnerability exists due to insufficient validation of user-supplied input within the expat library, when processing XML files. A remote attacker can pass specially crafted XML content to the affected library and perform a denial of service (DoS) attack.

Affected software

expat
Gentoo Linux
watchOS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
macOS
Slackware Linux
tvOS
iPadOS
Apple iOS
openEuler
IBM Tivoli Monitoring
IBM Rational ClearCase
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
expat
expat-help
expat-debuginfo
expat-devel
expat-debugsource
expat (Red Hat package)
Red Hat OpenShift Serverless
IBM Security SiteProtector System
IBM HTTP Server
NetWorker Management Console

How to mitigate CVE-2013-0340

Install update from vendor's website.

expat - update to 2.1.0
watchOS - update to 8.0 19R346
macOS - addressed in versions 10.15.7 19H1417, 11.6 20G165
tvOS - update to 15.0 19J346
iPadOS - update to 15.0 19A346
Apple iOS - update to 15.0 19A346
Red Hat OpenShift Serverless - update to 1
expat - update to 2.2.9-3
expat-help - update to 2.2.9-3
expat-debuginfo - update to 2.2.9-3
expat-devel - update to 2.2.9-3
expat-debugsource - update to 2.2.9-3
expat (Red Hat package) - addressed in versions 2.2.10-1.el8_4, 2.2.10-1.el8_6, 2.2.10-1.el8_8, 2.2.10-12.el9_0.4
IBM Security SiteProtector System - update to 3.1.1.20
IBM HTTP Server - addressed in versions 7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15
NetWorker Management Console - update to 19.12.0.1

External References

Related Security Bulletins