Jump to content

Advisories MDVSA-2009:316-2: expat


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in expat:

 

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,

as used in the XML-Twig module for Perl, allows context-dependent

attackers to cause a denial of service (application crash) via an

XML document with malformed UTF-8 sequences that trigger a buffer

over-read, related to the doProlog function in lib/xmlparse.c,

a different vulnerability than CVE-2009-2625 and CVE-2009-3720

(CVE-2009-3560).

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers

 

This update provides a solution to these vulnerabilities.

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0

customers.

 

Update:

 

SUSE discovered a regression with the previous patch fixing

CVE-2009-3560. This regression is now being addressed with this update.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...