LWN.net Logo

feedparser: denial of service

Package(s):feedparser CVE #(s):CVE-2012-2921
Created:May 23, 2012 Updated:April 10, 2013
Description: From the CVE entry:

Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.

Alerts:
Ubuntu USN-1449-1 2012-05-22
Fedora FEDORA-2012-8291 2012-06-01
Mageia MGASA-2012-0157 2012-07-10
Mandriva MDVSA-2013:118 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds