SUSE-SU-2017:0424-1 -- SLES expat, libexpat1ID: oval:org.secpod.oval:def:89044853 | Date: (C)2021-07-20 (M)2024-02-19 |
Class: PATCH | Family: unix |
This update for expat fixes the following security issues: - CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, made it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function. - CVE-2016-5300: The XML parser in Expat did not use sufficient entropy for hash initialization, which allowed context-dependent attackers to cause a denial of service via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876
Platform: |
SUSE Linux Enterprise Server 12 SP2 |