cbcvebase.
CVE-2019-15903
published 2019-09-04

CVE-2019-15903: In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleicloud_for_windows
appleios_13.3_and_ipados
appleitunes_12.10.3_for_windows
applemacos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007
appletvos
applewatchos
debianchromium< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
debianexpat< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
debianfirefox< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
debianfirefox-esr< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
debianlibxmltok< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
debianthunderbird< expat 2.2.7-2 (bookworm)expat 2.2.7-2 (bookworm)
googlechrome_chrome
libexpat_projectlibexpat< 2.2.82.2.8
mozillathunderbird>= 0 < 1:68.2.1-11:68.2.1-1
mozillathunderbird>= 0 < 1:68.2.1-11:68.2.1-1
mozillathunderbird>= 0 < 1:68.2.1-11:68.2.1-1
mozillathunderbird>= 0 < 1:68.2.1-11:68.2.1-1
mozillathunderbird>= 0 < 1:68.7.0+build1-0ubuntu0.16.04.21:68.7.0+build1-0ubuntu0.16.04.2
mozillathunderbird>= 0 < 1:68.2.2+build1-0ubuntu0.18.04.11:68.2.2+build1-0ubuntu0.18.04.1
mozillathunderbird>= 0 < 1:68.2.1+build1-0ubuntu0.18.04.11:68.2.1+build1-0ubuntu0.18.04.1
msrccm1_expat_2.4.1-1_on_cbl_mariner_1.0
pythonpython>= 2.7.0 < 2.7.172.7.17
pythonpython>= 3.5.0 < 3.5.83.5.8

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH