Description
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1977-1 | New python packages fix several vulnerabilities |
Ubuntu USN |
USN-890-1 | Expat vulnerabilities |
Ubuntu USN |
USN-890-2 | Python 2.5 vulnerabilities |
Ubuntu USN |
USN-890-3 | Python 2.4 vulnerabilities |
Ubuntu USN |
USN-890-4 | PyXML vulnerabilities |
Ubuntu USN |
USN-890-5 | XML-RPC for C and C++ vulnerabilities |
Ubuntu USN |
USN-890-6 | CMake vulnerabilities |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T06:38:30.003Z
Reserved: 2009-10-16T00:00:00.000Z
Link: CVE-2009-3720
No data.
Status : Modified
Published: 2009-11-03T16:30:12.563
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-3720
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN