[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2016-5300
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.

CVE-2012-6702
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

*OVAL
oval:org.secpod.oval:def:703167
CPE    6
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:libexpat:lib64expat1
cpe:/a:libexpat:libexpat1
cpe:/o:ubuntu:ubuntu_linux:14.04
...

© SecPod Technologies