5
CVSSv2

CVE-2012-2921

Published: 21/05/2012 Updated: 22/08/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Universal Feed Parser (aka feedparser or python-feedparser) prior to 5.1.2 allows remote malicious users to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.

Vulnerable Product Search on Vulmon Subscribe to Product

mark pilgrim feedparser 5.1.2

mark pilgrim feedparser

mark pilgrim feedparser 3.0

mark pilgrim feedparser 5.1

mark pilgrim feedparser 3.3

mark pilgrim feedparser 3.1

mark pilgrim feedparser 4.1

mark pilgrim feedparser 4.0.1

mark pilgrim feedparser 5.0

mark pilgrim feedparser 3.2

mark pilgrim feedparser 4.0.2

mark pilgrim feedparser 3.0.1

mark pilgrim feedparser 5.0.1

mark pilgrim feedparser 4.0

Vendor Advisories

Debian Bug report logs - #674167 CVE-2012-2921 Package: python-feedparser; Maintainer for python-feedparser is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-feedparser is src:feedparser (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date ...
Applications using feedparser could be made to crash if they fetched a specially crafted feed ...