Oval Definition:
oval:org.mitre.oval:def:6760
Revision Date
:
2014-06-23
Version
:
20
Title
:
DSA-1953 expat -- denial of service
Description
:
Jan Lieskovsky discovered an error in expat, an XML parsing C library, when parsing certain UTF-8 sequences, which can be exploited to crash an application using the library.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2009-3560
DSA-1953
Platform(s)
:
Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s)
:
expat
Definition Synopsis
Release section
Debian GNU/Linux 5.0 is installed
AND
Architecture section
Architecture dependent section
Supported architectures section
Installed architecture is s390
OR
Installed architecture is sparc
OR
Installed architecture is i386
OR
Installed architecture is powerpc
AND
Packages section
lib64expat1 is earlier than 2.0.1-4+lenny2
OR
lib64expat1-dev is earlier than 2.0.1-4+lenny2
OR
expat is earlier than 2.0.1-4+lenny2
OR
libexpat1-dev is earlier than 2.0.1-4+lenny2
OR
libexpat1 is earlier than 2.0.1-4+lenny2
OR
Architecture dependent section
Supported architectures section
Installed architecture is amd64
OR
Installed architecture is hppa
OR
Installed architecture is armel
OR
Installed architecture is mips
OR
Installed architecture is ia64
OR
Installed architecture is alpha
OR
Installed architecture is mipsel
OR
Installed architecture is arm
AND
Packages section
expat is earlier than 2.0.1-4+lenny2
OR
libexpat1-dev is earlier than 2.0.1-4+lenny2
OR
libexpat1 is earlier than 2.0.1-4+lenny2
OR
Release section
Debian GNU/Linux 4.0 is installed.
AND
Supported architectures section
Installed architecture is s390
OR
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is arm
OR
Installed architecture is i386
OR
Installed architecture is mips
OR
Installed architecture is ia64
OR
Installed architecture is alpha
OR
Installed architecture is powerpc
OR
Installed architecture is hppa
AND
Packages section
libexpat1 is earlier than 1.95.8-3.4+etch2
OR
expat is earlier than 1.95.8-3.4+etch2
OR
libexpat1-dev is earlier than 1.95.8-3.4+etch2
BACK