CVE Vulnerabilities

CVE-2012-2921

Published: May 21, 2012 | Modified: Aug 22, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.

Affected Software

Name Vendor Start Version End Version
Feedparser Mark_pilgrim * 5.1.1 (including)
Feedparser Mark_pilgrim 3.0 (including) 3.0 (including)
Feedparser Mark_pilgrim 3.0.1 (including) 3.0.1 (including)
Feedparser Mark_pilgrim 3.1 (including) 3.1 (including)
Feedparser Mark_pilgrim 3.2 (including) 3.2 (including)
Feedparser Mark_pilgrim 3.3 (including) 3.3 (including)
Feedparser Mark_pilgrim 4.0 (including) 4.0 (including)
Feedparser Mark_pilgrim 4.0.1 (including) 4.0.1 (including)
Feedparser Mark_pilgrim 4.0.2 (including) 4.0.2 (including)
Feedparser Mark_pilgrim 4.1 (including) 4.1 (including)
Feedparser Mark_pilgrim 5.0 (including) 5.0 (including)
Feedparser Mark_pilgrim 5.0.1 (including) 5.0.1 (including)
Feedparser Mark_pilgrim 5.1 (including) 5.1 (including)
Feedparser Mark_pilgrim 5.1.2 (including) 5.1.2 (including)
Feedparser Ubuntu devel *
Feedparser Ubuntu hardy *
Feedparser Ubuntu lucid *
Feedparser Ubuntu natty *
Feedparser Ubuntu oneiric *
Feedparser Ubuntu precise *
Feedparser Ubuntu quantal *
Feedparser Ubuntu raring *
Feedparser Ubuntu saucy *
Feedparser Ubuntu upstream *

References