CVE-2012-1147: Input Validation
Published Jul 3, 2012
·Updated
readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
Affected Software
11 affected components
Apple iOS and macOS=10.11.0
Apple iOS and macOS=10.11.1
Libexpat Project Libexpat<=2.0.1
Libexpat Project Libexpat=1.95.1
Libexpat Project Libexpat=1.95.2
Libexpat Project Libexpat=1.95.4
Libexpat Project Libexpat=1.95.5
Libexpat Project Libexpat=1.95.6
Libexpat Project Libexpat=1.95.7
Libexpat Project Libexpat=1.95.8
Libexpat Project Libexpat=2.0.0
Event History
Jul 3, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1147?
CVE-2012-1147 is classified as a denial of service vulnerability.
2
How do I fix CVE-2012-1147?
The recommended fix for CVE-2012-1147 is to upgrade to libexpat version 2.1.0 or later.
3
Which versions of libexpat are affected by CVE-2012-1147?
CVE-2012-1147 affects libexpat versions prior to 2.1.0.
4
What impact does CVE-2012-1147 have on affected systems?
CVE-2012-1147 can lead to file descriptor consumption, potentially causing denial of service.
5
Is macOS Yosemite vulnerable to CVE-2012-1147?
Yes, macOS Yosemite versions 10.11.0 and 10.11.1 are vulnerable to CVE-2012-1147.