[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2017:0424-1 -- SLES expat, libexpat1

ID: oval:org.secpod.oval:def:89044853Date: (C)2021-07-20   (M)2024-02-19
Class: PATCHFamily: unix




This update for expat fixes the following security issues: - CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, made it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function. - CVE-2016-5300: The XML parser in Expat did not use sufficient entropy for hash initialization, which allowed context-dependent attackers to cause a denial of service via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876

Platform:
SUSE Linux Enterprise Server 12 SP2
Product:
expat
libexpat1
Reference:
SUSE-SU-2017:0424-1
CVE-2012-6702
CVE-2016-5300
CVE    2
CVE-2016-5300
CVE-2012-6702
CPE    3
cpe:/o:suse:suse_linux_enterprise_server:12:sp2
cpe:/a:libexpat:expat
cpe:/a:libexpat1:libexpat1

© SecPod Technologies