First published: Mon Jun 20 2016(Updated: )
It was discovered that Expat unexpectedly called srand in certain circumstances. This could reduce the security of calling applications. (CVE-2012-6702) It was discovered that Expat incorrectly handled seeding the random number generator. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2016-5300)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/lib64expat1 | <2.1.0-7ubuntu0.16.04.2 | 2.1.0-7ubuntu0.16.04.2 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libexpat1 | <2.1.0-7ubuntu0.16.04.2 | 2.1.0-7ubuntu0.16.04.2 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/lib64expat1 | <2.1.0-7ubuntu0.15.10.2 | 2.1.0-7ubuntu0.15.10.2 |
Ubuntu Ubuntu | =15.10 | |
All of | ||
ubuntu/libexpat1 | <2.1.0-7ubuntu0.15.10.2 | 2.1.0-7ubuntu0.15.10.2 |
Ubuntu Ubuntu | =15.10 | |
All of | ||
ubuntu/lib64expat1 | <2.1.0-4ubuntu1.3 | 2.1.0-4ubuntu1.3 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/libexpat1 | <2.1.0-4ubuntu1.3 | 2.1.0-4ubuntu1.3 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/lib64expat1 | <2.0.1-7.2ubuntu1.4 | 2.0.1-7.2ubuntu1.4 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/libexpat1 | <2.0.1-7.2ubuntu1.4 | 2.0.1-7.2ubuntu1.4 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Expat vulnerabilities CVE-2012-6702 and CVE-2016-5300.
The vulnerability could reduce the security of calling applications.
Versions 2.0.1-7.2ubuntu1.4, 2.1.0-4ubuntu1.3, 2.1.0-7ubuntu0.15.10.2, and 2.1.0-7ubuntu0.16.04.2 are affected.
Updating libexpat1 to version 2.1.0-7ubuntu0.16.04.2 or higher.
More information can be found at the following references: [CVE-2012-6702](https://ubuntu.com/security/CVE-2012-6702), [CVE-2016-5300](https://ubuntu.com/security/CVE-2016-5300), [USN-3013-1](https://ubuntu.com/security/notices/USN-3013-1).