CVE Vulnerabilities

CVE-2012-6702

Published: Jun 16, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

Affected Software

NameVendorStart VersionEnd Version
LibexpatLibexpat_project*2.2.0 (excluding)
AudacityUbuntukinetic*
AudacityUbuntulunar*
AudacityUbuntumantic*
AyttmUbuntuprecise*
AyttmUbuntuwily*
AyttmUbuntuyakkety*
CableswigUbuntuprecise*
CableswigUbuntuwily*
CadaverUbuntuartful*
CadaverUbuntuprecise*
CadaverUbuntuwily*
CadaverUbuntuyakkety*
CadaverUbuntuzesty*
Coin3Ubuntuartful*
Coin3Ubuntuprecise*
Coin3Ubuntuwily*
Coin3Ubuntuyakkety*
Coin3Ubuntuzesty*
ExpatUbuntuesm-infra-legacy/trusty*
ExpatUbuntuesm-infra/xenial*
ExpatUbuntuprecise*
ExpatUbuntutrusty*
ExpatUbuntutrusty/esm*
ExpatUbuntuupstream*
ExpatUbuntuvivid/stable-phone-overlay*
ExpatUbuntuvivid/ubuntu-core*
ExpatUbuntuwily*
ExpatUbuntuxenial*
InsighttoolkitUbuntuesm-apps/xenial*
InsighttoolkitUbuntuprecise*
InsighttoolkitUbuntutrusty*
InsighttoolkitUbuntuwily*
InsighttoolkitUbuntuxenial*
KompozerUbuntuprecise*
Libparagui1.1Ubuntuprecise*
LibxmltokUbuntuhirsute*
LibxmltokUbuntutrusty*
LibxmltokUbuntuxenial*
MatanzaUbuntuartful*
MatanzaUbuntuprecise*
MatanzaUbuntuwily*
MatanzaUbuntuyakkety*
MatanzaUbuntuzesty*
ParaviewUbuntuplucky*
SimgearUbuntuprecise*
SitecopyUbuntuartful*
SitecopyUbuntuoracular*
SitecopyUbuntuplucky*
SitecopyUbuntuprecise*
SitecopyUbuntuwily*
SitecopyUbuntuyakkety*
SitecopyUbuntuzesty*
Swish-eUbuntuartful*
Swish-eUbuntuprecise*
Swish-eUbuntuwily*
Swish-eUbuntuyakkety*
Swish-eUbuntuzesty*
TdomUbuntuartful*
TdomUbuntuprecise*
TdomUbuntuwily*
TdomUbuntuyakkety*
TdomUbuntuzesty*
TlaUbuntuprecise*
TlaUbuntuwily*
TlaUbuntuyakkety*
TlaUbuntuzesty*
Vnc4Ubuntuartful*
Vnc4Ubuntubionic*
Vnc4Ubuntucosmic*
Vnc4Ubuntudisco*
Vnc4Ubuntueoan*
Vnc4Ubuntuesm-apps/bionic*
Vnc4Ubuntuesm-apps/xenial*
Vnc4Ubuntuesm-infra-legacy/trusty*
Vnc4Ubuntuprecise*
Vnc4Ubuntutrusty*
Vnc4Ubuntutrusty/esm*
Vnc4Ubuntuupstream*
Vnc4Ubuntuwily*
Vnc4Ubuntuxenial*
Vnc4Ubuntuyakkety*
Vnc4Ubuntuzesty*
VtkUbuntuprecise*
VtkUbuntuwily*
Wbxml2Ubuntuartful*
Wbxml2Ubuntuprecise*
Wbxml2Ubuntuwily*
Wbxml2Ubuntuyakkety*
Wbxml2Ubuntuzesty*
Wxwidgets2.6Ubuntuprecise*
Wxwidgets2.8Ubuntuprecise*
Wxwidgets2.8Ubuntuwily*
Xmlrpc-cUbuntuartful*
Xmlrpc-cUbuntubionic*
Xmlrpc-cUbuntucosmic*
Xmlrpc-cUbuntudevel*
Xmlrpc-cUbuntudisco*
Xmlrpc-cUbuntueoan*
Xmlrpc-cUbuntuesm-apps/bionic*
Xmlrpc-cUbuntuesm-apps/focal*
Xmlrpc-cUbuntuesm-apps/jammy*
Xmlrpc-cUbuntuesm-apps/noble*
Xmlrpc-cUbuntuesm-apps/xenial*
Xmlrpc-cUbuntuesm-infra-legacy/trusty*
Xmlrpc-cUbuntufocal*
Xmlrpc-cUbuntugroovy*
Xmlrpc-cUbuntuhirsute*
Xmlrpc-cUbuntuimpish*
Xmlrpc-cUbuntujammy*
Xmlrpc-cUbuntukinetic*
Xmlrpc-cUbuntulunar*
Xmlrpc-cUbuntumantic*
Xmlrpc-cUbuntunoble*
Xmlrpc-cUbuntuoracular*
Xmlrpc-cUbuntuplucky*
Xmlrpc-cUbuntuprecise*
Xmlrpc-cUbuntuquesting*
Xmlrpc-cUbuntutrusty*
Xmlrpc-cUbuntutrusty/esm*
Xmlrpc-cUbuntuwily*
Xmlrpc-cUbuntuxenial*
Xmlrpc-cUbuntuyakkety*
Xmlrpc-cUbuntuzesty*
XotclUbuntuartful*
XotclUbuntuprecise*
XotclUbuntuwily*
XotclUbuntuyakkety*
XotclUbuntuzesty*

References