CVE-2012-6702

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*
cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:13

Type Values Removed Values Added
References (CONFIRM) https://www.tenable.com/security/tns-2016-20 - Third Party Advisory () https://www.tenable.com/security/tns-2016-20 -
References (CONFIRM) https://source.android.com/security/bulletin/2016-11-01.html - Third Party Advisory () https://source.android.com/security/bulletin/2016-11-01.html -
References (GENTOO) https://security.gentoo.org/glsa/201701-21 - Third Party Advisory () https://security.gentoo.org/glsa/201701-21 -
References (MLIST) http://www.openwall.com/lists/oss-security/2016/06/04/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/06/04/1 -
References (MLIST) http://www.openwall.com/lists/oss-security/2016/06/03/8 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/06/03/8 -
References (UBUNTU) http://www.ubuntu.com/usn/USN-3010-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-3010-1 -
References (BID) http://www.securityfocus.com/bid/91483 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/91483 -
References (DEBIAN) http://www.debian.org/security/2016/dsa-3597 - Third Party Advisory () http://www.debian.org/security/2016/dsa-3597 -

25 Jan 2021, 15:44

Type Values Removed Values Added
CPE cpe:2.3:a:libexpat:expat:*:*:*:*:*:*:*:* cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

Information

Published : 2016-06-16 18:59

Updated : 2023-12-10 11:46


NVD link : CVE-2012-6702

Mitre link : CVE-2012-6702

CVE.ORG link : CVE-2012-6702


JSON object : View

Products Affected

libexpat_project

  • libexpat

debian

  • debian_linux

canonical

  • ubuntu_linux

google

  • android
CWE
CWE-310

Cryptographic Issues