4.3

CVE-2012-0876

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libexpat ProjectLibexpat Version < 2.1.0
PythonPython Version >= 2.6.0 < 2.6.8
PythonPython Version >= 2.7.0 < 2.7.3
PythonPython Version >= 3.1.0 < 3.1.5
PythonPython Version >= 3.2.0 < 3.2.3
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version11.04
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 SwEdition-
OracleSolaris Version11.3
RedhatStorage Version2.0
RedhatEnterprise Linux Eus Version6.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.526
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://bugs.python.org/issue13703#msg151870
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/52379
Third Party Advisory
VDB Entry