expat big2_toUtf8()函数XML文件解析拒绝服务漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BUGTRAQ ID: 37203 CVE ID: CVE-2009-3560 Expat是用C语言编写的XML解析器库。 Expat库的lib/xmltok.c文件中的big2_toUtf8函数存在拒绝服务漏洞。如果用户受骗打开了包含有畸形UTF-8序列的XML文档,就会在lib/xmlparse.c的doProlog函数中触发缓冲区越界读取,导致链接到Expat库上的应用崩溃。 James Clark Expat 2.0.1 厂商补丁: Debian ------ Debian已经为此发布了一个安全公告(DSA-1953-1)以及相应补丁: DSA-1953-1:New expat packages fix denial of service 链接:http://www.debian.org/security/2009/dsa-1953 补丁下载: Source archives: http://security.debian.org/pool/updates/main/e/expat/expat_1.95.8-3.4+etch2.diff.gz Size/MD5 checksum: 413321 e6d99f30014fccc0ffb9db1554ba1472 http://security.debian.org/pool/updates/main/e/expat/expat_1.95.8.orig.tar.gz Size/MD5 checksum: 318349 aff487543845a82fe262e6e2922b4c8e http://security.debian.org/pool/updates/main/e/expat/expat_1.95.8-3.4+etch2.dsc Size/MD5 checksum: 703 50e1e2ab47fe419e89ef671991ddb3f0 alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/e/expat/libexpat1_1.95.8-3.4+etch2_alpha.deb Size/MD5 checksum: 69460 59616e932bcd8c86ecd4998fe633f5ee...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息