CVE-2012-6702
MEDIUMlibexpat < 2.2.0 - Hash Collision via srand Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6702. PoCs published by codecat007.
AI-analyzed exploit summary This PoC demonstrates a vulnerability in the Expat XML parser (CVE-2012-6702) by repeatedly creating and freeing parsers to exploit a flaw in random value generation, leading to potential memory corruption or DoS conditions.
Description
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
Exploits (1)
This PoC demonstrates a vulnerability in the Expat XML parser (CVE-2012-6702) by repeatedly creating and freeing parsers to exploit a flaw in random value generation, leading to potential memory corruption or DoS conditions.
References (8)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N