CVE-2021-45960
published 2022-01-01CVE-2021-45960: In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g.…
PriorityP348high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.23%
89.9th percentile
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.3-1 (bookworm) | expat 2.4.3-1 (bookworm) |
| debian | libxmltok | < expat 2.4.3-1 (bookworm) | expat 2.4.3-1 (bookworm) |
| libexpat_project | libexpat | < 2.4.3 | 2.4.3 |
| msrc | cbl2_expat_2.4.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.3-1_on_cbl_mariner_1.0 | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| tenable | nessus | < 8.15.3 | 8.15.3 |
| tenable | nessus | >= 10.0.0 < 10.1.1 | 10.1.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pfmv-2r4f-j9mj: In Expat (aka libexpat) before 2
ghsa_unreviewed·2022-02-10
CVE-2021-45960 [HIGH] CWE-400 GHSA-pfmv-2r4f-j9mj: In Expat (aka libexpat) before 2
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
OSV
CVE-2021-45960: In Expat (aka libexpat) before 2
osv·2022-01-01·CVSS 8.8
CVE-2021-45960 [HIGH] CVE-2021-45960: In Expat (aka libexpat) before 2
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: Large number of prefixed XML attributes on a single tag can crash libexpat
vendor_redhat·2022-01-17·CVSS 8.8
CVE-2021-45960 [HIGH] CWE-1335 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
expat: Large number of prefixed XML attributes on a single tag can crash libexpat
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to buffer overrun. The highest threat from this vulnerability is to availability.
Statement: Red Hat Product Security has rated this CVE based on the configurations of a default install in the context of SELinux enforcement and services run as non privileged users.
Package: expat (Red Hat Enterprise Linux
Microsoft
In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory).
vendor_msrc·2022-01-11·CVSS 8.8
CVE-2021-45960 [HIGH] CWE-682 In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory).
In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the
Debian
CVE-2021-45960: expat - In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the...
vendor_debian·2021·CVSS 8.8
CVE-2021-45960 [HIGH] CVE-2021-45960: expat - In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the...
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Recent expat CVEs
bugzilla·2022-02-10·CVSS 8.8
[HIGH] Recent expat CVEs
Recent expat CVEs
Lately some expat CVEs popped up [1], the expat is sandboxed in the version 96+
but the ESR seems not to be covered. Could you please investigate if the vulnerabilities has any relevancy for the Firefox?
[1] https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=expat&search_type=all&isCpeNameSearch=false
Discussion:
[Tracking Requested - why for this release]: possible sec issues
---
Bobby, do you think RLBoxing expat on ESR was feasible?
(as a possible alternative to updating expat)
---
* CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 to CVE-2022-22827: needs to be verified, but on first glance I don't think we allow enough data into the parser to hit these.
* CVE-2022-23852: doesn't affect us, only affects "configurations with a n
Bugzilla
CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
bugzilla·2022-01-24·CVSS 8.8
CVE-2021-45960 [HIGH] CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
References:
https://github.com/libexpat/libexpat/issues/531
https://github.com/libexpat/libexpat/pull/534
https://bugzilla.mozilla.org/show_bug.cgi?id=1217609
http://www.openwall.com/lists/oss-security/2022/01/17/3
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 2044452]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2022:0951 https://access.redhat.com/errata/RHSA-2022:0951
---
This issue has been add
Bugzilla
Multiple invalid left shifts in libexpat
bugzilla·2015-10-22·CVSS 8.8
[HIGH] Multiple invalid left shifts in libexpat
Multiple invalid left shifts in libexpat
Created attachment 8677717
ubsan_results.txt
While fuzzing libexpat (2.1.0) I came a across a number of invalid left shifts.
I will attach the fixes I made to get past these errors. Please feel free to use these.
Discussion:
Created attachment 8677719
xmlparse.diff
Fixes for https://dxr.mozilla.org/mozilla-central/source/parser/expat/lib/xmlparse.c
---
Created attachment 8677720
xmltok.diff
Fixes for https://dxr.mozilla.org/mozilla-central/source/parser/expat/lib/xmltok.c
---
Can you file a bug in the Expat tracker (https://github.com/libexpat/libexpat) for the patch in xmlparse.c? The problems addressed in the patch for xmltok.c have been fixed in https://sourceforge.net/p/expat/bugs/529/.
---
Fixes are available. Upstream issue: https
http://www.openwall.com/lists/oss-security/2022/01/17/3https://bugzilla.mozilla.org/show_bug.cgi?id=1217609https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/issues/531https://github.com/libexpat/libexpat/pull/534https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220121-0004/https://www.debian.org/security/2022/dsa-5073https://www.tenable.com/security/tns-2022-05http://www.openwall.com/lists/oss-security/2022/01/17/3https://bugzilla.mozilla.org/show_bug.cgi?id=1217609https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/issues/531https://github.com/libexpat/libexpat/pull/534https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220121-0004/https://www.debian.org/security/2022/dsa-5073https://www.tenable.com/security/tns-2022-05
2022-01-01
Published