Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 12.04 LTS USN-1527-1 Critical Expat Denial of Service

ubuntu
Calendar Grey August 10, 2012
Scroller Ubuntu
Excessive resource consumption by Expat could lead to service outages. Ensure your Ubuntu is up to date for enhanced security.
Expat could be made to cause a denial of service by consuming excessive CPUand memory resources.

Summary

Expat could be made to cause a denial of service by consuming excessive CPU

and memory resources.

Software Description:

- expat: XML parsing C library - example application

Details:

It was discovered that Expat computed hash values without restricting the

ability to trigger hash collisions predictably. If a user or application linked

against Expat were tricked into opening a crafted XML file, an attacker could

cause a denial of service by consuming excessive CPU resources. (CVE-2012-0876)

Tim Boddy discovered that Expat did not properly handle memory reallocation

when processing XML files. If a user or application linked against Expat were

tricked into opening a crafted XML file, an attacker could cause a denial of

service by consuming excessive memory resources. This issue only affected

Ubuntu 8.04 LTS, 10.04 LTS, 11.04 and 11.10. (CVE-2012-1148)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  lib64expat1                     2.0.1-7.2ubuntu1.1
  libexpat1                       2.0.1-7.2ubuntu1.1
  libexpat1-udeb                  2.0.1-7.2ubuntu1.1

Ubuntu 11.10:
  lib64expat1                     2.0.1-7ubuntu3.11.10.1
  libexpat1                       2.0.1-7ubuntu3.11.10.1
  libexpat1-udeb                  2.0.1-7ubuntu3.11.10.1

Ubuntu 11.04:
  lib64expat1                     2.0.1-7ubuntu3.11.04.1
  libexpat1                       2.0.1-7ubuntu3.11.04.1
  libexpat1-udeb                  2.0.1-7ubuntu3.11.04.1

Ubuntu 10.04 LTS:
  lib64expat1                     2.0.1-7ubuntu1.1
  libexpat1                       2.0.1-7ubuntu1.1
  libexpat1-udeb                  2.0.1-7ubuntu1.1

Ubuntu 8.04 LTS:
  lib64expat1                     2.0.1-0ubuntu1.2
  libexpat1                       2.0.1-0ubuntu1.2
  libexpat1-udeb                  2.0.1-0ubuntu1.2

After a standard system upgrade you need to restart any applications linked
against Expat to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-1527-1

CVE-2012-0876, CVE-2012-1148

Severity
critical
Lowest
Low
Medium
High
Critical

August 10, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.