Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 12.04 LTS USN-3013-1 Critical: XML-RPC DoS Vulnerabilities

ubuntu
Calendar Grey June 20, 2016
Scroller Ubuntu
Several vulnerabilities were fixed in the XML-RPC library for C and C++, impacting Ubuntu 12.04 LTS installations.
Several security issues were fixed in XML-RPC for C and C++.

Summary

Several security issues were fixed in XML-RPC for C and C++.

Software Description:

- xmlrpc-c: Lightweight RPC library based on XML and HTTP

Details:

It was discovered that the Expat code in XML-RPC for C and C++ unexpectedly

called srand in certain circumstances. This could reduce the security of

calling applications. (CVE-2012-6702)

It was discovered that the Expat code in XML-RPC for C and C++ incorrectly

handled seeding the random number generator. A remote attacker could

possibly use this issue to cause a denial of service. (CVE-2016-5300)

Gustavo Grieco discovered that the Expat code in XML-RPC for C and C++

incorrectly handled malformed XML data. If a user or application linked

against XML-RPC for C and C++ were tricked into opening a crafted XML file,

an attacker could cause a denial of service, or possibly execute arbitrary

code. (CVE-2016-0718)

It was discovered that the Expat code in XML-RPC for C and C++ incorrectly

handled malformed XML dat...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libxmlrpc-c++4                  1.16.33-3.1ubuntu5.2
  libxmlrpc-core-c3               1.16.33-3.1ubuntu5.2

After a standard system upgrade you need to restart any applications linked
against XML-RPC for C and C++ to effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-3013-1

CVE-2012-6702, CVE-2015-1283, CVE-2016-0718, CVE-2016-4472,

CVE-2016-5300

Severity
critical
Lowest
Low
Medium
High
Critical

June 20, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.