expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences
Published Dec 4, 2009
5.0
MEDIUMCVSS 2.0
EPSS 24.31%
Description
The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
Affected products
No data.
Configuration 1
- 2.0.1
Running on/with
- n/a
Configuration 2
- ≥ 2.0.35 · < 2.0.64
- ≥ 2.2.0 · < 2.2.17
No data.
Red Hat Enterprise Linux 3
expat-0:1.95.5-6.2
Fixed · RHSA-2009:1625
Red Hat Enterprise Linux 4
expat-0:1.95.7-4.el4_8.2
Fixed · RHSA-2009:1625
Red Hat Enterprise Linux 5
expat-0:1.95.8-8.3.el5_4.2
Fixed · RHSA-2009:1625
Red Hat JBoss Enterprise Application Platform 6.4
n/a
Fixed · RHSA-2017:3239
Red Hat JBoss Web Server 1.0
n/a
Fixed · RHSA-2011:0896
Red Hat Enterprise Linux 5
xmlrpc-c
Will not fix
Red Hat Enterprise Linux 6
compat-expat1
Not affected
Red Hat Enterprise Linux 6
expat
Not affected
Red Hat Enterprise Linux 7
expat
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | expat-0:1.95.5-6.2 | Fixed | RHSA-2009:1625 |
| Red Hat Enterprise Linux 4 | expat-0:1.95.7-4.el4_8.2 | Fixed | RHSA-2009:1625 |
| Red Hat Enterprise Linux 5 | expat-0:1.95.8-8.3.el5_4.2 | Fixed | RHSA-2009:1625 |
| Red Hat JBoss Enterprise Application Platform 6.4 | n/a | Fixed | RHSA-2017:3239 |
| Red Hat JBoss Web Server 1.0 | n/a | Fixed | RHSA-2011:0896 |
| Red Hat Enterprise Linux 5 | xmlrpc-c | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | compat-expat1 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | expat | Not affected | n/a |
| Red Hat Enterprise Linux 7 | expat | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (45 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 24.31% (0.24313) | 97.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 24.31% (0.24313) | 97.58th | v5 (v2026.06.15) |
| Mar 4, 2026 | 2.83% (0.02830) | 85.93th | v4 (v2025.03.14) |
| Mar 1, 2026 | 0.78% (0.00783) | 73.53th | v4 (v2025.03.14) |
| Feb 4, 2026 | 2.83% (0.02830) | 85.83th | v4 (v2025.03.14) |
| Feb 1, 2026 | 0.78% (0.00783) | 73.40th | v4 (v2025.03.14) |
| Jan 4, 2026 | 2.83% (0.02830) | 85.76th | v4 (v2025.03.14) |
| Jan 1, 2026 | 0.78% (0.00783) | 73.33th | v4 (v2025.03.14) |
| Dec 4, 2025 | 2.83% (0.02830) | 85.71th | v4 (v2025.03.14) |
| Dec 1, 2025 | 0.78% (0.00783) | 73.08th | v4 (v2025.03.14) |
| Nov 4, 2025 | 2.83% (0.02830) | 85.67th | v4 (v2025.03.14) |
| Nov 1, 2025 | 0.78% (0.00783) | 73.12th | v4 (v2025.03.14) |
| Oct 4, 2025 | 2.83% (0.02830) | 85.66th | v4 (v2025.03.14) |
| Oct 1, 2025 | 0.78% (0.00783) | 73.03th | v4 (v2025.03.14) |
| Sep 4, 2025 | 2.96% (0.02961) | 85.97th | v4 (v2025.03.14) |
| Sep 1, 2025 | 0.82% (0.00820) | 73.60th | v4 (v2025.03.14) |
| Aug 4, 2025 | 2.35% (0.02349) | 84.26th | v4 (v2025.03.14) |
| Aug 1, 2025 | 0.60% (0.00602) | 68.69th | v4 (v2025.03.14) |
| Jul 13, 2025 | 2.24% (0.02244) | 83.87th | v4 (v2025.03.14) |
| Jul 4, 2025 | 4.48% (0.04481) | 88.61th | v4 (v2025.03.14) |
| Jul 1, 2025 | 1.18% (0.01175) | 77.83th | v4 (v2025.03.14) |
| Jun 4, 2025 | 4.48% (0.04481) | 88.54th | v4 (v2025.03.14) |
| Jun 1, 2025 | 1.18% (0.01175) | 77.75th | v4 (v2025.03.14) |
| May 5, 2025 | 4.48% (0.04481) | 88.44th | v4 (v2025.03.14) |
| May 1, 2025 | 1.18% (0.01175) | 77.63th | v4 (v2025.03.14) |
| Apr 16, 2025 | 3.88% (0.03877) | 87.59th | v4 (v2025.03.14) |
| Apr 13, 2025 | 1.01% (0.01010) | 75.20th | v4 (v2025.03.14) |
| Apr 2, 2025 | 3.88% (0.03877) | 87.20th | v4 (v2025.03.14) |
| Apr 1, 2025 | 1.01% (0.01010) | 75.14th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.88% (0.03877) | 87.17th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.15% (0.02150) | 73.72th | v4 (v2025.03.14) |
| Mar 26, 2025 | 3.88% (0.03877) | 87.08th | v4 (v2025.03.14) |
| Mar 25, 2025 | 1.01% (0.01010) | 74.97th | v4 (v2025.03.14) |
| Mar 21, 2025 | 3.88% (0.03877) | 87.26th | v4 (v2025.03.14) |
| Mar 20, 2025 | 1.01% (0.01010) | 75.17th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.88% (0.03877) | 87.47th | v4 (v2025.03.14) |
| Dec 17, 2024 | 4.02% (0.04023) | 91.98th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.15% (0.01146) | 85.42th | v3 (v2023.03.01) |
| Jul 14, 2024 | 1.20% (0.01201) | 85.36th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.27% (0.01275) | 84.13th | v3 (v2023.03.01) |
| Nov 2, 2023 | 2.60% (0.02602) | 89.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.56% (0.01563) | 85.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (61)
- http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165 x_refsource_CONFIRMPermissions Required
- http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165 x_refsource_CONFIRMBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSEThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html vendor-advisoryx_refsource_SUSEThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html vendor-advisoryx_refsource_SUSEThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html vendor-advisoryx_refsource_SUSEThird Party AdvisoryVDB Entry
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLISTBroken Link
- http://mail.python.org/pipermail/expat-bugs/2009-November/002846.html mailing-listx_refsource_MLISTExploit
- http://marc.info/?l=bugtraq&m=130168502603566&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://secunia.com/advisories/37537 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38231 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38832 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/39478 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/41701 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/43300 third-party-advisoryx_refsource_SECUNIABroken Link
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026 vendor-advisoryx_refsource_SLACKWAREMailing ListThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1 vendor-advisoryx_refsource_SUNALERTMailing ListThird Party Advisory
- http://www.debian.org/security/2009/dsa-1953 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:316 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.redhat.com/support/errata/RHSA-2011-0896.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/37203 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1023278 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-890-1 vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-890-6 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/0896 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2011/0359 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-3560 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=533174 x_refsource_CONFIRMIssue TrackingPatch
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2009-3560
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10613 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12942 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6883 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2009-3560
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00394.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.