Lucene search

K
archlinuxArch LinuxASA-201606-14
HistoryJun 13, 2016 - 12:00 a.m.

lib32-expat: multiple issues

2016-06-1300:00:00
Arch Linux
lists.archlinux.org
54

0.007 Low

EPSS

Percentile

81.0%

  • CVE-2012-6702 (predictable random numbers)

It was found that when calling XML_Parse ahead of rand(), it causes the
pseudo random generator to generate non-random predictable numbers.

  • CVE-2016-5300 (denial of service)

It was found that original fix for CVE-2012-0876 used too little
entropy for the hash initialization. This issue can be used to perform
a hash collision based denial of service attack.

OSVersionArchitecturePackageVersionFilename
anyanyanylib32-expat< 2.1.1-3UNKNOWN