USN-3010-1: Expat vulnerabilities
It was discovered that Expat unexpectedly called srand in certain circumstances. This could reduce the security of calling applications. (CVE-2012-6702) It was discovered that Expat incorrectly handled seeding the random number generator. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2016-5300)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability in USN-3010-1?
Expat vulnerabilities CVE-2012-6702 and CVE-2016-5300.
How does the vulnerability in USN-3010-1 affect the security of calling applications?
The vulnerability could reduce the security of calling applications.
Which versions of libexpat1 are affected by the vulnerability in USN-3010-1?
Versions 2.0.1-7.2ubuntu1.4, 2.1.0-4ubuntu1.3, 2.1.0-7ubuntu0.15.10.2, and 2.1.0-7ubuntu0.16.04.2 are affected.
What is the recommended remedy for the vulnerability in USN-3010-1?
Updating libexpat1 to version 2.1.0-7ubuntu0.16.04.2 or higher.
Where can I find more information about the vulnerability in USN-3010-1?
More information can be found at the following references: [CVE-2012-6702](https://ubuntu.com/security/CVE-2012-6702), [CVE-2016-5300](https://ubuntu.com/security/CVE-2016-5300), [USN-3013-1](https://ubuntu.com/security/notices/USN-3013-1).