The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "expat",
"binary_version": "2.1.0-4ubuntu1.3"
},
{
"binary_name": "lib64expat1",
"binary_version": "2.1.0-4ubuntu1.3"
},
{
"binary_name": "lib64expat1-dev",
"binary_version": "2.1.0-4ubuntu1.3"
},
{
"binary_name": "libexpat1",
"binary_version": "2.1.0-4ubuntu1.3"
},
{
"binary_name": "libexpat1-dev",
"binary_version": "2.1.0-4ubuntu1.3"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8",
"binary_version": "1.33.06-0ubuntu1"
},
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.06-0ubuntu1"
},
{
"binary_name": "libxmlrpc-core-c3",
"binary_version": "1.33.06-0ubuntu1"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.06-0ubuntu1"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.06-0ubuntu1"
}
]
}{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "expat",
"binary_version": "2.1.0-7ubuntu0.16.04.2"
},
{
"binary_name": "lib64expat1",
"binary_version": "2.1.0-7ubuntu0.16.04.2"
},
{
"binary_name": "lib64expat1-dev",
"binary_version": "2.1.0-7ubuntu0.16.04.2"
},
{
"binary_name": "libexpat1",
"binary_version": "2.1.0-7ubuntu0.16.04.2"
},
{
"binary_name": "libexpat1-dev",
"binary_version": "2.1.0-7ubuntu0.16.04.2"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.14-1ubuntu1"
},
{
"binary_name": "libxmlrpc-c++8v5",
"binary_version": "1.33.14-1ubuntu1"
},
{
"binary_name": "libxmlrpc-core-c3",
"binary_version": "1.33.14-1ubuntu1"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.14-1ubuntu1"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.14-1ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.14-8build1"
},
{
"binary_name": "libxmlrpc-c++8v5",
"binary_version": "1.33.14-8build1"
},
{
"binary_name": "libxmlrpc-core-c3",
"binary_version": "1.33.14-8build1"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.14-8build1"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.14-8build1"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.14-8build2"
},
{
"binary_name": "libxmlrpc-c++8v5",
"binary_version": "1.33.14-8build2"
},
{
"binary_name": "libxmlrpc-core-c3",
"binary_version": "1.33.14-8build2"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.14-8build2"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.14-8build2"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.14-10"
},
{
"binary_name": "libxmlrpc-c++8v5",
"binary_version": "1.33.14-10"
},
{
"binary_name": "libxmlrpc-core-c3",
"binary_version": "1.33.14-10"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.14-10"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.14-10"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++8-dev",
"binary_version": "1.33.14-12build2"
},
{
"binary_name": "libxmlrpc-c++8t64",
"binary_version": "1.33.14-12build2"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.33.14-12build2"
},
{
"binary_name": "libxmlrpc-core-c3t64",
"binary_version": "1.33.14-12build2"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.33.14-12build2"
}
]
}{
"binaries": [
{
"binary_name": "libxmlrpc-c++9",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "libxmlrpc-c++9-dev",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "libxmlrpc-core-c3-dev",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "libxmlrpc-core-c3t64",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "libxmlrpc-util-dev",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "libxmlrpc-util4",
"binary_version": "1.59.03-10.1"
},
{
"binary_name": "xmlrpc-api-utils",
"binary_version": "1.59.03-10.1"
}
]
}