Expat contains a flaw in the handling of XML documents that may allow a remote denial of service. The issue is due to the 'big2_toUtf8()' function in lib/xmltok.c not validating user-supplied input. With a specially crafted XML file containing malformed UTF-8 sequences, a context-dependent attacker can cause the service to crash.
Classification
Location:
Context Dependent
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Third-Party Solution
Exploit:
Exploit Unknown
Disclosure:
Third-party Verified
OSVDB:
Web Related
Solution
Multiple vendors have released an upgrade to address this vulnerability. Check the vendor advisory, changelog, or solution in the references section for details.