CVE-2009-3720
Last modified
CVE-2009-3720 is a vulnerability of currently unknown severity. The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.. EPSS estimates a 27.92% chance of exploitation in the next 30 days.
Description
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libexpat Project | Libexpat | 2.0.1 |
| Apache | Http Server | >= 2.0.35, < 2.0.64 |
| Apache | Http Server | >= 2.2.0, < 2.2.17 |
References
- http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=logMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlThird Party Advisory, VDB Entry
- http://mail.python.org/pipermail/expat-bugs/2009-January/002781.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=130168502603566&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/37324Broken Link
- http://secunia.com/advisories/37537Broken Link
- http://secunia.com/advisories/37925Broken Link
- http://secunia.com/advisories/38050Broken Link
- http://secunia.com/advisories/38231Broken Link
- http://secunia.com/advisories/38794Broken Link
- http://secunia.com/advisories/38832Broken Link
- http://secunia.com/advisories/38834Broken Link
- http://secunia.com/advisories/39478Broken Link
- http://secunia.com/advisories/41701Broken Link
- http://secunia.com/advisories/42326Broken Link
- http://secunia.com/advisories/42338Broken Link
- http://secunia.com/advisories/43300Broken Link
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026Mailing List, Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1990430&group_id=10127&atid=110127Mailing List, Third Party Advisory
- http://svn.python.org/view?view=rev&revision=74429Permissions Required, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:211Permissions Required, Third Party Advisory
- http://www.securitytracker.com/id?1023160Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-890-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-890-6Third Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=280615Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=531697Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7112Mailing List, Third Party Advisory
- http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=logMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlThird Party Advisory, VDB Entry
- http://mail.python.org/pipermail/expat-bugs/2009-January/002781.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=130168502603566&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/37324Broken Link
- http://secunia.com/advisories/37537Broken Link
- http://secunia.com/advisories/37925Broken Link
- http://secunia.com/advisories/38050Broken Link
- http://secunia.com/advisories/38231Broken Link
- http://secunia.com/advisories/38794Broken Link
- http://secunia.com/advisories/38832Broken Link
- http://secunia.com/advisories/38834Broken Link
- http://secunia.com/advisories/39478Broken Link
- http://secunia.com/advisories/41701Broken Link
- http://secunia.com/advisories/42326Broken Link
- http://secunia.com/advisories/42338Broken Link
- http://secunia.com/advisories/43300Broken Link
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026Mailing List, Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1990430&group_id=10127&atid=110127Mailing List, Third Party Advisory
- http://svn.python.org/view?view=rev&revision=74429Permissions Required, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:211Permissions Required, Third Party Advisory
- http://www.securitytracker.com/id?1023160Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-890-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-890-6Third Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=280615Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=531697Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7112Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3720?
How severe is CVE-2009-3720?
How do I fix CVE-2009-3720?
Are you affected by CVE-2009-3720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
