CVE-2009-3720
Summary
| CVE | CVE-2009-3720 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-03 16:30:12 UTC |
| Updated | 2026-07-20 14:35:41 UTC |
| Description | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Application | Libexpat Project | Libexpat | 2.0.1 | All | All | All |
| Application | Python | Python | All | All | All | All |
| Application | Python | Pyxml | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Red Hat update for 4Suite - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:013 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory, VDB Entry |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:014 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| oss-security - Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| [SECURITY] Fedora 10 Update: expat-2.0.1-8.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:216 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| VMware ESX Server Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Apache APR-util Multiple Denial of Service Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:012 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory, VDB Entry |
| Ubuntu update for expat - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| [SECURITY] Fedora 12 Update: expat-2.0.1-8.fc12 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Ubuntu update for cmake - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:211 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Permissions Required, Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Expat XML Parser / Bugs / #464 Parser crash with specially formatted UTF-8 sequences | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Mailing List, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| VMware vMA Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| oss-security - Re: Re: expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| oss-security - Re: Regarding expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| expat UTF-8 Sequence Parsing Flaw Lets Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Gentoo Bug 280615 - <dev-libs/expat-2.0.1-r2 Bug 1990430 UTF-8 parser crash (CVE-2009-2625?) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| oss-security - Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| oss-security - Re: Re: Regarding expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:018 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| [SECURITY] Fedora 14 Update: udunits2-2.1.19-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:218 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link |
| [SECURITY] Fedora 14 Update: libtlen-0-0.10.20060309.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Mailing List, Third Party Advisory |
| Red Hat update for PyXML - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| [SECURITY] Fedora 12 Update: PyXML-0.8.4-17.fc12 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | svn.python.org | Permissions Required, Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:215 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Fedora update for udunits2 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Support / Security / Advisories / / MDVSA-2009:219 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| oss-security - Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430] | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| [Expat-bugs] [ expat-Bugs-1990430 ] Parser crash with specially formatted UTF-8 sequences | af854a3a-2127-422b-91ae-364da2661108 | mail.python.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| CVS Info for project expat | af854a3a-2127-422b-91ae-364da2661108 | expat.cvs.sourceforge.net | Mailing List, Third Party Advisory |
| oss-security - Re: expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| [Security-announce] VMSA-2010-0004 ESX Service Console and vMA third party updates | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Broken Link |
| USN-890-6: CMake vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:212 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| VMware ESX Server 4 Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| oss-security - Re: Re: expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory, VDB Entry |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2009:217 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Support / Security / Advisories / / MDVSA-2009:220 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| oss-security - expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Bug 531697 – CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking |
| CVS Info for project expat | af854a3a-2127-422b-91ae-364da2661108 | expat.cvs.sourceforge.net | Exploit |
| [SECURITY] Fedora 12 Update: libtlen-0-0.10.20060309.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| '[security bulletin] HPSBUX02645 SSRT100387 rev.1 - HP-UX Apache Web Server, Remote Information Discl' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| [SECURITY] Fedora 13 Update: udunits2-2.1.19-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| oss-security - Re: Re: expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| oss-security - Regarding expat bug 1990430 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| [SECURITY] Fedora 13 Update: libtlen-0-0.10.20060309.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Mailing List, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Third Party Advisory |
| Fedora update for PyXML - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| USN-890-1: Expat vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-03-05 | Tomas Hoger | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3720 The Red Hat Security Response Team has rated this issue as having moderate security impact in Python, a future update may address this flaw. If a system has PyXML installed, Python will use PyXML for expat-related functions and is then not vulnerable to the issue. |
There are currently no legacy QID mappings associated with this CVE.