CVE-2009-3720
expat - denial of service
EPSS 1.7%
Description
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
How to fix CVE-2009-3720
To remediate CVE-2009-3720, upgrade the affected package to a fixed version below.
- Debian/audacity—upgrade to 1.3.2-1 or later
- Debian/cadaver—no fix listed
- —upgrade to 2.6.0-6 or later
- —upgrade to 4.0.0~CMake~6f54f1602475+ds1-1 or later
- —upgrade to 2.0.1-5 or later
- —upgrade to 1.95.8-3.4+etch1 or later
- —upgrade to 2.0.14-2 or later
- —upgrade to 8.71~dfsg-2 or later
- —no fix listed
- —no fix listed
- —upgrade to 0.10.0-1 or later
- —upgrade to 3.6.2-1 or later
- —upgrade to 1.3.6p1-1 or later
- —upgrade to 2.10.0-1 or later
- —upgrade to 0.8.3~20080525-1 or later
- —upgrade to 1.3.5+dfsg-15 or later
- —upgrade to 2.1.8-4 or later
- —upgrade to 1.06.27-1.1 or later
- —upgrade to 1.6.5-1.2 or later
Is CVE-2009-3720 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (19)
- from 0, < 1.3.2-1
- from 0
- from 0, < 2.6.0-6
- from 0, < 4.0.0~CMake~6f54f1602475+ds1-1
- from 0, < 2.0.1-5
- from 0, < 1.95.8-3.4+etch1
- from 0, < 2.0.14-2
- from 0, < 8.71~dfsg-2
- from 0
- from 0
- from 0, < 0.10.0-1