CVE-2019-15903
published 2019-09-04CVE-2019-15903: In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.71%
93.2th percentile
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | — | — |
| apple | ios_13.3_and_ipados | — | — |
| apple | itunes_12.10.3_for_windows | — | — |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| debian | chromium | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| debian | expat | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| debian | firefox | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| debian | firefox-esr | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| debian | libxmltok | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| debian | thunderbird | < expat 2.2.7-2 (bookworm) | expat 2.2.7-2 (bookworm) |
| chrome_chrome | — | — | |
| libexpat_project | libexpat | < 2.2.8 | 2.2.8 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1-1 | 1:68.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:68.7.0+build1-0ubuntu0.16.04.2 | 1:68.7.0+build1-0ubuntu0.16.04.2 |
| mozilla | thunderbird | >= 0 < 1:68.2.2+build1-0ubuntu0.18.04.1 | 1:68.2.2+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:68.2.1+build1-0ubuntu0.18.04.1 | 1:68.2.1+build1-0ubuntu0.18.04.1 |
| msrc | cm1_expat_2.4.1-1_on_cbl_mariner_1.0 | — | — |
| python | python | >= 2.7.0 < 2.7.17 | 2.7.17 |
| python | python | >= 3.5.0 < 3.5.8 | 3.5.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2025-01-13·CVSS 6.8
CVE-2019-15903 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, cont
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2022-07-19·CVSS 5.0
CVE-2021-46143 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, o
Ubuntu
VTK vulnerabilities
vendor_ubuntu·2021-03-15
CVE-2018-20843 VTK vulnerabilities
Title: VTK vulnerabilities
Summary: Several security issues were fixed in VTK.
It was discovered that VTK incorrectly handled certain XML files in the
embedded Expat library. An attacker could possibly use this issue to cause
a denial of service or expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2020-04-21·CVSS 8.8
CVE-2019-11745 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, bypass
same-origin restrictions, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11757, CVE-2019-11758, CVE-2019-11759,
CVE-2019-11760, CVE-2019-11761, CVE-2019-11762, CVE-2019-11763,
CVE-2019-11764, CVE-2019-17005, CVE-2019-17008, CVE-2019-17010,
CVE-2019-17011, CVE-2019-17012, CVE-2019-17016, CVE-2019-17017,
CVE-2019-17022, CVE-2019-17024, CVE-2019-17026, CVE-2019-20503,
CVE-2020-6798,
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (LibExpat) — CVE-2019-15903
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-15903 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (LibExpat) — CVE-2019-15903
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (LibExpat) vulnerability
CVE: CVE-2019-15903
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Apple
CVE-2019-15903: iCloud for Windows 10.9
vendor_apple·2019-12-11·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: iCloud for Windows 10.9
Apple Security Update: About the security content of iCloud for Windows 10.9
Product: iCloud for Windows
Version: 10.9
CVE: CVE-2019-15903
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-15903: iTunes 12.10.3 for Windows
vendor_apple·2019-12-11·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: iTunes 12.10.3 for Windows
Apple Security Update: About the security content of iTunes 12.10.3 for Windows
Product: iTunes 12.10.3 for Windows
CVE: CVE-2019-15903
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-15903: iCloud for Windows 7.16
vendor_apple·2019-12-11·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: iCloud for Windows 7.16
Apple Security Update: About the security content of iCloud for Windows 7.16
Product: iCloud for Windows
Version: 7.16
CVE: CVE-2019-15903
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-15903: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2019-15903
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-15903: iOS 13.3 and iPadOS 13.3
vendor_apple·2019-12-10·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: iOS 13.3 and iPadOS 13.3
Apple Security Update: About the security content of iOS 13.3 and iPadOS 13.3
Product: iOS 13.3 and iPadOS
Version: 13.3
CVE: CVE-2019-15903
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-15903: tvOS 13.3
vendor_apple·2019-12-10·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15903
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Ubuntu
Thunderbird regression
vendor_ubuntu·2019-12-10·CVSS 7.5
[HIGH] Thunderbird regression
Title: Thunderbird regression
Summary: USN-4202-1 caused a regression in Thunderbird.
USN-4202-1 fixed vulnerabilities in Thunderbird. After upgrading, Thunderbird
created a new profile for some users. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to
Apple
CVE-2019-15903: watchOS 6.1.1
vendor_apple·2019-12-10·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-15903
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-11-26·CVSS 7.5
CVE-2019-11755 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass same-origin restrictions, conduct
cross-site scripting (XSS) attacks, or execute arbitrary code.
(CVE-2019-11757, CVE-2019-11758, CVE-2019-
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2019-10-23
CVE-2018-6156 Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass security
restrictions, bypass same-origin restrictions, conduct cross-site
scripting (XSS) attacks, bypass content security policy (CSP) protections,
or execute arbitrary code.
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Chrome
Stable Channel Update for Desktop: CVE-2019-13711
vendor_chrome·2019-10-22·CVSS 5.3
CVE-2019-13711 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13711
Stable Channel Update for Desktop
CVE-2019-13711: Cross-context information leak. Reported by David Erceg on 2019-07-20
[$500][ 1004341 ] Medium CVE-2019-15903: Buffer overflow in expat
Reported by Sebastian Pipping on 2019-09-16
Severity: medium
BSD
OpenBSD 6.5 Errata 011: SECURITY FIX
bsd_advisories·2019-09-14·CVSS 7.5
CVE-2019-15903 [HIGH] OpenBSD 6.5 Errata 011: SECURITY FIX
OpenBSD 6.5 Errata 011: SECURITY FIX
011: SECURITY FIX: September 14, 2019
All architectures Libexpat 2.2.6 was affected by the heap overflow CVE-2019-15903.
BSD
OpenBSD 6.4 Errata 024: SECURITY FIX
bsd_advisories·2019-09-14·CVSS 7.5
CVE-2019-15903 [HIGH] OpenBSD 6.4 Errata 024: SECURITY FIX
OpenBSD 6.4 Errata 024: SECURITY FIX
024: SECURITY FIX: September 14, 2019
All architectures Libexpat 2.2.6 was affected by the heap overflow CVE-2019-15903.
Ubuntu
Expat vulnerability
vendor_ubuntu·2019-09-12
CVE-2019-15903 Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to expose sensitive information if it received a
specially crafted XML file.
It was discovered that Expat incorrectly handled certain XML files.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerability
vendor_ubuntu·2019-09-12
CVE-2019-15903 Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to expose sensitive information if it received
a specially crafted XML file.
USN-4132-1 fixed a vulnerability in Expat. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Expat incorrectly handled certain XML files.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
In libexpat before 2.2.8 crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNu
vendor_msrc·2019-09-10·CVSS 7.5
CVE-2019-15903 [HIGH] CWE-125 In libexpat before 2.2.8 crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNu
In libexpat before 2.2.8 crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to
Red Hat
expat: heap-based buffer over-read via crafted XML input
vendor_redhat·2019-09-04·CVSS 7.5
CVE-2019-15903 [HIGH] CWE-122 expat: heap-based buffer over-read via crafted XML input
expat: heap-based buffer over-read via crafted XML input
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: expat (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Package: xmlrpc-c (Red Hat E
Debian
CVE-2019-15903: chromium - In libexpat before 2.2.8, crafted XML input could fool the parser into changing ...
vendor_debian·2019·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: chromium - In libexpat before 2.2.8, crafted XML input could fool the parser into changing ...
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
libxmltok vulnerabilities
osv·2025-01-13·CVSS 6.8
CVE-2015-1283 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, whi
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
GHSA
GHSA-w829-6hpw-frjf: In libexpat before 2
ghsa_unreviewed·2022-05-24
CVE-2019-15903 [HIGH] CWE-125 GHSA-w829-6hpw-frjf: In libexpat before 2
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
OSV
thunderbird vulnerabilities
osv·2020-04-21·CVSS 8.8
CVE-2019-11757 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, bypass
same-origin restrictions, conduct cross-site scripting (XSS) attacks, or
execute arbitrary code. (CVE-2019-11757, CVE-2019-11758, CVE-2019-11759,
CVE-2019-11760, CVE-2019-11761, CVE-2019-11762, CVE-2019-11763,
CVE-2019-11764, CVE-2019-17005, CVE-2019-17008, CVE-2019-17010,
CVE-2019-17011, CVE-2019-17012, CVE-2019-17016, CVE-2019-17017,
CVE-2019-17022, CVE-2019-17024, CVE-2019-17026, CVE-2019-20503,
CVE-2020-6798, CVE-2020-6800, CVE-2020-6805, CVE-2020-6806, CVE-2020-6807,
CVE-2020
OSV
thunderbird regression
osv·2019-12-10·CVSS 7.5
[HIGH] thunderbird regression
thunderbird regression
USN-4202-1 fixed vulnerabilities in Thunderbird. After upgrading, Thunderbird
created a new profile for some users. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass
OSV
thunderbird vulnerabilities
osv·2019-11-26·CVSS 7.5
CVE-2019-11755 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that a specially crafted S/MIME message with an inner
encryption layer could be displayed as having a valid signature in some
circumstances, even if the signer had no access to the encrypted message.
An attacker could potentially exploit this to spoof the message author.
(CVE-2019-11755)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass security restrictions, bypass same-origin restrictions, conduct
cross-site scripting (XSS) attacks, or execute arbitrary code.
(CVE-2019-11757, CVE-2019-11758, CVE-2019-11759, CVE-2019-11760,
CVE-2019-11761, CVE-2019-11762, CVE-2019-1176
OSV
CVE-2019-15903: In libexpat before 2
osv·2019-09-04·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903: In libexpat before 2
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
No detection rules found.
No public exploits indexed.
Bugzilla
Take patches from expat 2.2.8
bugzilla·2019-09-30·CVSS 7.5
[HIGH] Take patches from expat 2.2.8
Take patches from expat 2.2.8
[email protected] received an email on September 14th. Surprisingly, there seems to be no Bugzilla entry for this issue.
If we want to fix just the heap overflow, then we need to look at the patch at:
https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43
Am 14.09.19 um 23:00 schrieb Sebastian Pipping:
> Hi!
>
>
> I would like to let you know that Expat 2.2.8 [1] has been released. It
> fixes heap buffer over-read CVE-2019-15903 [2] and other issues [3].
>
> If you happen to have patches for Expat that are still required with
> 2.2.8, please send them my way.
>
> Thank you!
>
> Best
>
>
>
> Sebastian
>
>
> [1] https://github.com/libexpat/libexpat/releases/tag/R_2_2_8
> [2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-
Bugzilla
CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [fedora-all]
bugzilla·2019-09-16·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [fedora-all]
CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [epel-7]
bugzilla·2019-09-16·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [epel-7]
CVE-2019-15903 mingw-expat: expat: heap-based buffer over-read via crafted XML input [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template
Bugzilla
CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input [fedora-all]
bugzilla·2019-09-16·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input [fedora-all]
CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input
bugzilla·2019-09-16·CVSS 7.5
CVE-2019-15903 [HIGH] CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input
CVE-2019-15903 expat: heap-based buffer over-read via crafted XML input
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Reference:
https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43
https://github.com/libexpat/libexpat/issues/317
https://github.com/libexpat/libexpat/issues/342
https://github.com/libexpat/libexpat/pull/318
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 1752596]
Created mingw-expat tracking bugs for this issue:
Affects: fedora-all [bug 1752597]
---
Created mingw-expat tracking bugs for this issu
Crowdstrike
How a Generalized Validation Testing Approach Improves Efficiency
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How a Generalized Validation Testing Approach Improves Efficiency
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
How a Generalized Validation Testing Approach Improves Efficiency
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How a Generalized Validation Testing Approach Improves Efficiency
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://packetstormsecurity.com/files/154503/Slackware-Security-Advisory-expat-Updates.htmlhttp://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.htmlhttp://packetstormsecurity.com/files/154947/Slackware-Security-Advisory-mozilla-firefox-Updates.htmlhttp://seclists.org/fulldisclosure/2019/Dec/23http://seclists.org/fulldisclosure/2019/Dec/26http://seclists.org/fulldisclosure/2019/Dec/27http://seclists.org/fulldisclosure/2019/Dec/30https://access.redhat.com/errata/RHSA-2019:3210https://access.redhat.com/errata/RHSA-2019:3237https://access.redhat.com/errata/RHSA-2019:3756https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43https://github.com/libexpat/libexpat/issues/317https://github.com/libexpat/libexpat/issues/342https://github.com/libexpat/libexpat/pull/318https://lists.debian.org/debian-lts-announce/2019/11/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2019/11/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG/https://seclists.org/bugtraq/2019/Dec/17https://seclists.org/bugtraq/2019/Dec/21https://seclists.org/bugtraq/2019/Dec/23https://seclists.org/bugtraq/2019/Nov/1https://seclists.org/bugtraq/2019/Nov/24https://seclists.org/bugtraq/2019/Oct/29https://seclists.org/bugtraq/2019/Sep/30https://seclists.org/bugtraq/2019/Sep/37https://security.gentoo.org/glsa/201911-08https://security.netapp.com/advisory/ntap-20190926-0004/https://support.apple.com/kb/HT210785https://support.apple.com/kb/HT210788https://support.apple.com/kb/HT210789https://support.apple.com/kb/HT210790https://support.apple.com/kb/HT210793https://support.apple.com/kb/HT210794https://support.apple.com/kb/HT210795https://usn.ubuntu.com/4132-1/https://usn.ubuntu.com/4132-2/https://usn.ubuntu.com/4165-1/https://usn.ubuntu.com/4202-1/https://usn.ubuntu.com/4335-1/https://www.debian.org/security/2019/dsa-4530https://www.debian.org/security/2019/dsa-4549https://www.debian.org/security/2019/dsa-4571https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.tenable.com/security/tns-2021-11http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://packetstormsecurity.com/files/154503/Slackware-Security-Advisory-expat-Updates.htmlhttp://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.htmlhttp://packetstormsecurity.com/files/154947/Slackware-Security-Advisory-mozilla-firefox-Updates.htmlhttp://seclists.org/fulldisclosure/2019/Dec/23http://seclists.org/fulldisclosure/2019/Dec/26http://seclists.org/fulldisclosure/2019/Dec/27http://seclists.org/fulldisclosure/2019/Dec/30https://access.redhat.com/errata/RHSA-2019:3210https://access.redhat.com/errata/RHSA-2019:3237https://access.redhat.com/errata/RHSA-2019:3756https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43https://github.com/libexpat/libexpat/issues/317https://github.com/libexpat/libexpat/issues/342https://github.com/libexpat/libexpat/pull/318https://lists.debian.org/debian-lts-announce/2019/11/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2019/11/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG/https://seclists.org/bugtraq/2019/Dec/17https://seclists.org/bugtraq/2019/Dec/21https://seclists.org/bugtraq/2019/Dec/23https://seclists.org/bugtraq/2019/Nov/1https://seclists.org/bugtraq/2019/Nov/24https://seclists.org/bugtraq/2019/Oct/29https://seclists.org/bugtraq/2019/Sep/30https://seclists.org/bugtraq/2019/Sep/37https://security.gentoo.org/glsa/201911-08https://security.netapp.com/advisory/ntap-20190926-0004/
+ 18 more references
2019-09-04
Published