CVE-2012-0876: Medium severity libexpat vulnerability
Published Jul 3, 2012
·Updated
Last updated 24 July 2024
Other sources
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values ...
— Debian
Affected Software
24 affected componentsFixes available
Libexpat Project Libexpat<2.1.0
Python Python>=2.6.0<2.6.8
Python Python>=2.7.0<2.7.3
Python Python>=3.1.0<3.1.5
Python Python>=3.2.0<3.2.3
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Canonical Ubuntu Linux=8.04
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Oracle Solaris=11.3
redhat Storage=2.0
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Eus=6.2
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server Aus=6.2
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
debian/expat
2.2.10-2+deb11u52.2.10-2+deb11u62.5.0-1+deb12u12.7.1-1
debian/xmlrpc-c
1.33.14-91.33.14-111.59.03-71.59.03-8
Remediation
Event History
Jul 3, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:58 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·12:49 AM
RemedyDescriptionSeverityAffected Software
Apr 20, 2025
Data Sourced
via Debian·01:26 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-0876?
CVE-2012-0876 is considered to have a medium severity due to its potential to cause denial of service through CPU exhaustion.
2
How do I fix CVE-2012-0876?
To fix CVE-2012-0876, update to expat version 2.1.0 or later, as well as the appropriate patched versions for other affected software.
3
Which software is affected by CVE-2012-0876?
CVE-2012-0876 affects expat versions prior to 2.1.0 and various versions of Python and Red Hat Enterprise Linux, among others.
4
Can CVE-2012-0876 be exploited remotely?
Yes, CVE-2012-0876 can potentially be exploited by sending a specially crafted XML file from a remote attacker.
5
What kind of impact does CVE-2012-0876 have?
The impact of CVE-2012-0876 can lead to denial of service through increased CPU consumption when processing malicious XML files.