Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in expat
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in expat
ID: USN-1527-1
Distribution: Ubuntu
Plattformen: Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Fr, 10. August 2012, 08:01
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1148
Applikationen: expat

Originalnachricht


--===============9019529066822907204==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="45Z9DzgjV8m4Oswq"
Content-Disposition: inline


--45Z9DzgjV8m4Oswq
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-1527-1
August 10, 2012

expat vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

Expat could be made to cause a denial of service by consuming excessive CPU
and memory resources.

Software Description:
- expat: XML parsing C library - example application

Details:

It was discovered that Expat computed hash values without restricting the
ability to trigger hash collisions predictably. If a user or application linked
against Expat were tricked into opening a crafted XML file, an attacker could
cause a denial of service by consuming excessive CPU resources. (CVE-2012-0876)

Tim Boddy discovered that Expat did not properly handle memory reallocation
when processing XML files. If a user or application linked against Expat were
tricked into opening a crafted XML file, an attacker could cause a denial of
service by consuming excessive memory resources. This issue only affected
Ubuntu 8.04 LTS, 10.04 LTS, 11.04 and 11.10. (CVE-2012-1148)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
lib64expat1 2.0.1-7.2ubuntu1.1
libexpat1 2.0.1-7.2ubuntu1.1
libexpat1-udeb 2.0.1-7.2ubuntu1.1

Ubuntu 11.10:
lib64expat1 2.0.1-7ubuntu3.11.10.1
libexpat1 2.0.1-7ubuntu3.11.10.1
libexpat1-udeb 2.0.1-7ubuntu3.11.10.1

Ubuntu 11.04:
lib64expat1 2.0.1-7ubuntu3.11.04.1
libexpat1 2.0.1-7ubuntu3.11.04.1
libexpat1-udeb 2.0.1-7ubuntu3.11.04.1

Ubuntu 10.04 LTS:
lib64expat1 2.0.1-7ubuntu1.1
libexpat1 2.0.1-7ubuntu1.1
libexpat1-udeb 2.0.1-7ubuntu1.1

Ubuntu 8.04 LTS:
lib64expat1 2.0.1-0ubuntu1.2
libexpat1 2.0.1-0ubuntu1.2
libexpat1-udeb 2.0.1-0ubuntu1.2

After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1527-1
CVE-2012-0876, CVE-2012-1148

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.0.1-7.2ubuntu1.1
https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu3.11.10.1
https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu3.11.04.1
https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu1.1
https://launchpad.net/ubuntu/+source/expat/2.0.1-0ubuntu1.2


--45Z9DzgjV8m4Oswq
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJQJIytAAoJENaSAD2qAscK6awQAKpRGtV9uJWD/AmQUxPeMUwS
cJRkTGuYSZmlIE61Ioe/8ZCjNWWEk1dWuC4s5rEk3jpIwVT7vSUkKu0YEVhceQdM
6sEbyfGebjJU/jBEHQedOAvdjvsDyKfLXbyJe6G+Ta2oijEz32cSrKkrI6HqJu4f
J20wBBs8XuLpue7wmyhKxyggRVzk2asHHjdWys388Uov+uhQoAy5df8bITDERX0r
B6mU7+Eu19aKpPCzk7ZeV30Xxfcx/QqM0pPKjJrqy3dcpAaAAmx7EUEJamU5Qeol
S8I5cFMDHBVk7vqKT1anO8prLct+ie1MK4U1VmWUBYavHCQqYjEkGS/3ZsySUIJw
YmrRUryH6+hzFxjyZ5O3Qt+FJbg4r2e987+i69+a5p6QEEfXs8Jr/Tnc326bXU3C
y5ibTT7ioaMQKxvYdzu4dh1nnlULpHnVYqUv8Z/GiC26DZ3/q9RvqVfm+h98Hn0k
1sUnZSizS+tI/ZJrN4EkQWSJA8AdBS9OadypLq+Ahes0kt4Yqm3Cv21rq0eIKiUs
hAzGY3eOrxoQuqOxGhbTTcKbNAW8uuGsAWItuOGLEhfBnsvbbmOWaxFL82fTfDZu
07A+Kbi3+rwz+riNXaZ3ePXK/EZUVlwy4zbVz/RJE9vdT5td4u9mMpL24aThNYVi
oJoG99M8Vc+Xy5uLcAYW
=h/eU
-----END PGP SIGNATURE-----

--45Z9DzgjV8m4Oswq--


--===============9019529066822907204==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============9019529066822907204==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung