Back

MEDIUM

expat: buffer over-read and crash on XML with malformed UTF-8 sequences

Published Nov 3, 2009

Description

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (97)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 3, 2009
Updated Aug 7, 2024
Reserved Oct 16, 2009
NVD
Status Modified
Modified Jul 20, 2026
Red Hat
Severity Moderate
Public date Jan 17, 2009
ENISA EUVD
Assigner redhat
Published Nov 3, 2009
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-3693