Mandriva Linux Security Advisory 2009-316 – The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than and CVE-2009-3720. Packages for 2008.0 are being provided due to extended support for Corporate products. This update provides a solution to these vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83498/MDVSA-2009-316.txt
Source: https://packetstormsecurity.com/files/83498/Mandriva-Linux-Security-Advisory-2009-316.html

