libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexpat | Libexpat_project | * | 2.8.0 (excluding) |
| Red Hat Hardened Images | RedHat | expat-main-2.8.0-0.1.hum1 | * |
| Ayttm | Ubuntu | esm-apps/xenial | * |
| Cableswig | Ubuntu | esm-apps/xenial | * |
| Cadaver | Ubuntu | esm-apps/xenial | * |
| Coin3 | Ubuntu | esm-apps/xenial | * |
| Expat | Ubuntu | esm-infra/xenial | * |
| Gdcm | Ubuntu | esm-apps/xenial | * |
| Insighttoolkit4 | Ubuntu | esm-apps/xenial | * |
| Libxmltok | Ubuntu | esm-apps/xenial | * |
| Matanza | Ubuntu | devel | * |
| Matanza | Ubuntu | esm-apps/focal | * |
| Matanza | Ubuntu | esm-apps/jammy | * |
| Matanza | Ubuntu | esm-apps/noble | * |
| Matanza | Ubuntu | esm-apps/resolute | * |
| Matanza | Ubuntu | esm-apps/xenial | * |
| Matanza | Ubuntu | jammy | * |
| Matanza | Ubuntu | noble | * |
| Matanza | Ubuntu | questing | * |
| Matanza | Ubuntu | resolute | * |
| Smart | Ubuntu | esm-apps/xenial | * |
| Swish-e | Ubuntu | esm-apps/xenial | * |
| Tdom | Ubuntu | esm-apps/xenial | * |
| Vnc4 | Ubuntu | esm-apps/xenial | * |
| Vtk | Ubuntu | esm-apps/xenial | * |
| Wbxml2 | Ubuntu | esm-apps/xenial | * |
| Xmlrpc-c | Ubuntu | esm-apps/xenial | * |