Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS: USN-1527-2 Critical: XML-RPC DoS Threat

ubuntu
Calendar Grey September 10, 2012
Scroller Ubuntu
Mitigating xmlrpc-c vulnerabilities is essential to defend against denial of service attacks targeting Ubuntu systems. Implementing these steps can enhance security
XML-RPC for C and C++ could be made to cause a denial of service by consuming excessive CPU and memory resources.

Summary

XML-RPC for C and C++ could be made to cause a denial of service by consuming

excessive CPU and memory resources.

Software Description:

- xmlrpc-c: Lightweight RPC library based on XML and HTTP

Details:

USN-1527-1 fixed vulnerabilities in Expat. This update provides the

corresponding updates for XML-RPC for C and C++. Both issues described in the

original advisory affected XML-RPC for C and C++ in Ubuntu 10.04 LTS, 11.04,

11.10 and 12.04 LTS.

Original advisory details:

It was discovered that Expat computed hash values without restricting the

ability to trigger hash collisions predictably. If a user or application

linked against Expat were tricked into opening a crafted XML file, an attacker

could cause a denial of service by consuming excessive CPU resources.

(CVE-2012-0876)

Tim Boddy discovered that Expat did not properly handle memory reallocation

when processing XML files. If a user or application linked against Expat were

tricked into open...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libxmlrpc-core-c3               1.16.33-3.1ubuntu5.1

Ubuntu 11.10:
  libxmlrpc-core-c3-0             1.16.32-0ubuntu4.1

Ubuntu 11.04:
  libxmlrpc-core-c3-0             1.16.32-0ubuntu3.1

Ubuntu 10.04 LTS:
  libxmlrpc-core-c3               1.06.27-1ubuntu7.1

After a standard system upgrade you need to restart any applications linked
against XML-RPC for C and C++ to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-1527-2

https://ubuntu.com/security/notices/USN-1527-1

CVE-2012-0876, CVE-2012-1148

Severity
critical
Lowest
Low
Medium
High
Critical

September 10, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.