CVE-2012-0876: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 5.7% chance of exploitation in the next 30 days.

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

Affected products

  • Canonical Ubuntu Linux: version 8.04 only; version 10.04 only; version 11.04 only; version 11.10 only; version 12.04 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Libexpat Project Libexpat: before 2.1.0 (fixed in 2.1.0)
  • Oracle Solaris: version 11.3 only
  • Python Python: from 2.6.0, before 2.6.8 (fixed in 2.6.8); from 2.7.0, before 2.7.3 (fixed in 2.7.3); from 3.1.0, before 3.1.5 (fixed in 3.1.5); from 3.2.0, before 3.2.3 (fixed in 3.2.3)
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.2 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.2 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Red Hat Storage: version 2.0 only

Published 2012-07-03. Last modified 2026-06-16.