RHSA-2009:1572: Moderate: 4Suite security update

Published Nov 10, 2009
·
Updated

The 4Suite package contains XML-related tools and libraries for Python,including 4DOM, 4XSLT, 4XPath, 4RDF, and 4XPointer.A buffer over-read flaw was found in the way 4Suite's XML parser handlesmalformed UTF-8 sequences when processing XML files. A specially-craftedXML file could cause applications using the 4Suite library to crash whileparsing the file. (CVE-2009-3720)Note: In Red Hat Enterprise Linux 3, this flaw only affects a non-defaultconfiguration of the 4Suite package: configurations where the beta versionof the cDomlette module is enabled.All 4Suite users should upgrade to this updated package, which contains abackported patch to correct this issue. After installing the updatedpackage, applications using the 4Suite XML-related tools and libraries mustbe restarted for the update to take effect.

Affected Software

1 affected component
4Suite 4Suite

Remediation

Event History

Nov 10, 2009
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2009:1572?

The severity of RHSA-2009:1572 is categorized as moderate.

2

What does the vulnerability RHSA-2009:1572 affect?

RHSA-2009:1572 affects the 4Suite package, specifically its XML-related tools and libraries.

3

How do I fix RHSA-2009:1572?

To fix RHSA-2009:1572, update the 4Suite package to the latest version provided by your vendor.

4

What types of flaws are addressed in RHSA-2009:1572?

RHSA-2009:1572 addresses a buffer over-read flaw in 4Suite's XML parser.

5

Can malformed UTF-8 sequences exploit RHSA-2009:1572?

Yes, malformed UTF-8 sequences can be used to exploit the vulnerability identified in RHSA-2009:1572.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203