CVE-2012-6702: Medium severity Libexpat Project Libexpat vulnerability
Expat, when used in a parser that has not called XMLSetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2012-6702?
CVE-2012-6702 is a vulnerability in Expat that allows context-dependent attackers to defeat cryptographic protection mechanisms.
Which software is affected by CVE-2012-6702?
Google Android, Canonical Ubuntu Linux, Debian Debian Linux, and the Libexpat Project's Libexpat are affected by CVE-2012-6702.
What is the severity of CVE-2012-6702?
CVE-2012-6702 has a severity rating of medium with a CVSS score of 5.9.
How do I fix CVE-2012-6702 on Debian?
To fix CVE-2012-6702 on Debian, update the 'expat' package to version 2.2.0 or higher.
Where can I find more information about CVE-2012-6702?
You can find more information about CVE-2012-6702 on the MITRE CVE database, OSS Security mailing list, and Ubuntu's security notices.