UBUNTU-CVE-2012-0876
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-0876
UBUNTU-CVE-2012-0876
Summary:
Details: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
References: https://ubuntu.com/security/CVE-2012-0876, http://blog.gmane.org/gmane.text.xml.expat.bugs/month=20120301, http://www.openwall.com/lists/oss-security/2012/03/09/1, https://rhn.redhat.com/errata/RHSA-2012-0731.html, https://ubuntu.com/security/notices/USN-1527-1, https://ubuntu.com/security/notices/USN-1527-2, https://ubuntu.com/security/notices/USN-1613-1, https://ubuntu.com/security/notices/USN-1613-2, https://www.cve.org/CVERecord?id=CVE-2012-0876
Affected packages
Package
Name: coin3
Purl: pkg:deb/ubuntu/coin3?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
