First published: Fri Aug 10 2012(Updated: )
It was discovered that Expat computed hash values without restricting the ability to trigger hash collisions predictably. If a user or application linked against Expat were tricked into opening a crafted XML file, an attacker could cause a denial of service by consuming excessive CPU resources. (CVE-2012-0876) Tim Boddy discovered that Expat did not properly handle memory reallocation when processing XML files. If a user or application linked against Expat were tricked into opening a crafted XML file, an attacker could cause a denial of service by consuming excessive memory resources. This issue only affected Ubuntu 8.04 LTS, 10.04 LTS, 11.04 and 11.10. (CVE-2012-1148)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/lib64expat1 | <2.0.1-0ubuntu1.2 | 2.0.1-0ubuntu1.2 |
Ubuntu Ubuntu | =8.04 | |
All of | ||
ubuntu/libexpat1-udeb | <2.0.1-0ubuntu1.2 | 2.0.1-0ubuntu1.2 |
Ubuntu Ubuntu | =8.04 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-0ubuntu1.2 | 2.0.1-0ubuntu1.2 |
Ubuntu Ubuntu | =8.04 | |
All of | ||
ubuntu/lib64expat1 | <2.0.1-7.2ubuntu1.1 | 2.0.1-7.2ubuntu1.1 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/libexpat1-udeb | <2.0.1-7.2ubuntu1.1 | 2.0.1-7.2ubuntu1.1 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-7.2ubuntu1.1 | 2.0.1-7.2ubuntu1.1 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/lib64expat1 | <2.0.1-7ubuntu3.11.10.1 | 2.0.1-7ubuntu3.11.10.1 |
Ubuntu Ubuntu | =11.10 | |
All of | ||
ubuntu/libexpat1-udeb | <2.0.1-7ubuntu3.11.10.1 | 2.0.1-7ubuntu3.11.10.1 |
Ubuntu Ubuntu | =11.10 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-7ubuntu3.11.10.1 | 2.0.1-7ubuntu3.11.10.1 |
Ubuntu Ubuntu | =11.10 | |
All of | ||
ubuntu/lib64expat1 | <2.0.1-7ubuntu3.11.04.1 | 2.0.1-7ubuntu3.11.04.1 |
Ubuntu Ubuntu | =11.04 | |
All of | ||
ubuntu/libexpat1-udeb | <2.0.1-7ubuntu3.11.04.1 | 2.0.1-7ubuntu3.11.04.1 |
Ubuntu Ubuntu | =11.04 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-7ubuntu3.11.04.1 | 2.0.1-7ubuntu3.11.04.1 |
Ubuntu Ubuntu | =11.04 | |
All of | ||
ubuntu/lib64expat1 | <2.0.1-7ubuntu1.1 | 2.0.1-7ubuntu1.1 |
Ubuntu Ubuntu | =10.04 | |
All of | ||
ubuntu/libexpat1-udeb | <2.0.1-7ubuntu1.1 | 2.0.1-7ubuntu1.1 |
Ubuntu Ubuntu | =10.04 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-7ubuntu1.1 | 2.0.1-7ubuntu1.1 |
Ubuntu Ubuntu | =10.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-1527-1 is moderate.
To fix the Expat vulnerabilities in Ubuntu 8.04, update the lib64expat1 package to version 2.0.1-0ubuntu1.2 or above.
To fix the Expat vulnerabilities in Ubuntu 12.04, update the libexpat1 package to version 2.0.1-7.2ubuntu1.1 or above.
To fix the Expat vulnerabilities in Ubuntu 11.10, update the lib64expat1 package to version 2.0.1-7ubuntu3.11.10.1 or above.
To fix the Expat vulnerabilities in Ubuntu 11.04, update the lib64expat1 package to version 2.0.1-7ubuntu3.11.04.1 or above.