Lucene search

K
ubuntuUbuntuUSN-890-5
HistoryFeb 18, 2010 - 12:00 a.m.

XML-RPC for C and C++ vulnerabilities

2010-02-1800:00:00
ubuntu.com
37

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8 High

AI Score

Confidence

High

0.129 Low

EPSS

Percentile

95.5%

Releases

  • Ubuntu 9.10

Packages

  • xmlrpc-c -

Details

USN-890-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for XML-RPC for C and C++.

Original advisory details:

Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that Expat did
not properly process malformed XML. If a user or application linked against
Expat were tricked into opening a crafted XML file, an attacker could cause
a denial of service via application crash. (CVE-2009-2625, CVE-2009-3720)

It was discovered that Expat did not properly process malformed UTF-8
sequences. If a user or application linked against Expat were tricked into
opening a crafted XML file, an attacker could cause a denial of service via
application crash. (CVE-2009-3560)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchlibxmlrpc-core-c3< 1.06.27-1ubuntu6.1UNKNOWN
Ubuntu9.10noarchlibxmlrpc-c3< 1.06.27-1ubuntu6.1UNKNOWN
Ubuntu9.10noarchlibxmlrpc-c3-dev< 1.06.27-1ubuntu6.1UNKNOWN
Ubuntu9.10noarchlibxmlrpc-core-c3-dev< 1.06.27-1ubuntu6.1UNKNOWN
Ubuntu9.10noarchxml-rpc-api2cpp< 1.06.27-1ubuntu6.1UNKNOWN
Ubuntu9.10noarchxml-rpc-api2txt< 1.06.27-1ubuntu6.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

8 High

AI Score

Confidence

High

0.129 Low

EPSS

Percentile

95.5%