Expat, when used in a parser that has not called...
Vulnerability Description
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6702
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.tenable.com/security/tns-2016-20
- http://www.securityfocus.com/bid/91483
- http://www.debian.org/security/2016/dsa-3597
- http://www.openwall.com/lists/oss-security/2016/06/04/1
- http://www.openwall.com/lists/oss-security/2016/06/03/8
- https://security.gentoo.org/glsa/201701-21
- https://source.android.com/security/bulletin/2016-11-01.html
- http://www.ubuntu.com/usn/USN-3010-1
More from libexpat project
View All →Affected Vendor
libexpat project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.