MGASA-2016-0227

Source
https://advisories.mageia.org/MGASA-2016-0227.html
Import Source
https://advisories.mageia.org/MGASA-2016-0227.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0227
Related
Published
2016-06-17T05:58:14Z
Modified
2016-06-20T15:46:09Z
Summary
Updated expat packages fix security vulnerabilities
Details

Updated expat packages fix security vulnerabilities:

An issue was introduced when CVE-2012-0876 was addressed. Stefan Sørensen discovered that the use of the function XML_Parse() seeds the random number generator generating repeated outputs for rand() calls (CVE-2012-6702).

Due to an incomplete solution for CVE-2012-0876, the parser poorly seeds the random number generator allowing an attacker to cause a denial of service (CPU consumption) via an XML file with crafted identifiers (CVE-2016-5300).

References
Credits

Affected packages

Mageia:5 / expat

Package

Name
expat
Purl
pkg:rpm/mageia/expat?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0-9.3.mga5

Ecosystem specific

{
    "section": "core"
}