CVE-2024-45490
published 2024-08-30CVE-2024-45490: An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.69%
74.5th percentile
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios18.2_and_ipados18.2 | — | — |
| apple | ipados17.7.3 | — | — |
| apple | macos_sequoia | — | — |
| apple | macossonoma14.7.2 | — | — |
| apple | macosventura13.7.2 | — | — |
| apple | tvos18.2 | — | — |
| apple | visionos2.2 | — | — |
| apple | watchos11.2 | — | — |
| debian | expat | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| libexpat_project | libexpat | < 2.6.3 | 2.6.3 |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
expat vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
libxmltok vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] libxmltok vulnerabilities
libxmltok vulnerabilities
USN-7001-1 fixed vulnerabilities in xmltol library. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input
length was provided. An attacker could use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45491)
OSV
expat vulnerabilities
osv·2024-09-12·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
libxmltok vulnerabilities
osv·2024-09-12·CVSS 7.5
CVE-2024-45490 [HIGH] libxmltok vulnerabilities
libxmltok vulnerabilities
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input length
was provided. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2024-45491)
OSV
CVE-2024-45490: An issue was discovered in libexpat before 2
osv·2024-08-30·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
GHSA
GHSA-4hvh-m426-wv8w: An issue was discovered in libexpat before 2
ghsa_unreviewed·2024-08-30
CVE-2024-45490 [CRITICAL] CWE-190 GHSA-4hvh-m426-wv8w: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: NULL Pointer Dereference, Improper Validation of Integrity Check Value, Improper Restriction of XML External Entity Reference, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a Denial-of-Servi
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Apple
CVE-2024-45490: visionOS2.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: visionOS2.2
Apple Security Update: About the security content of visionOS2.2
Product: visionOS2.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Apple
CVE-2024-44225: macOSVentura13.7.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: macOSVentura13.7.2
Apple Security Update: About the security content of macOSVentura13.7.2
Product: macOSVentura13.7.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-54514: tvOS18.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: tvOS18.2
Apple Security Update: About the security content of tvOS18.2
Product: tvOS18.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-54514: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: iPadOS17.7.3
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: iPadOS17.7.3
Apple Security Update: About the security content of iPadOS17.7.3
Product: iPadOS17.7.3
CVE: CVE-2024-45490
Component: CVE-2024-45490
Apple
CVE-2024-54514: iOS18.2 and iPadOS18.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: iOS18.2 and iPadOS18.2
Apple Security Update: About the security content of iOS18.2 and iPadOS18.2
Product: iOS18.2 and iPadOS18.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: watchOS11.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: watchOS11.2
Apple Security Update: About the security content of watchOS11.2
Product: watchOS11.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-44225: macOSSonoma14.7.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: macOSSonoma14.7.2
Apple Security Update: About the security content of macOSSonoma14.7.2
Product: macOSSonoma14.7.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: iOS18.2 and iPadOS18.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: iOS18.2 and iPadOS18.2
Apple Security Update: About the security content of iOS18.2 and iPadOS18.2
Product: iOS18.2 and iPadOS18.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-54514: macOSVentura13.7.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: macOSVentura13.7.2
Apple Security Update: About the security content of macOSVentura13.7.2
Product: macOSVentura13.7.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: macOSSonoma14.7.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: macOSSonoma14.7.2
Apple Security Update: About the security content of macOSSonoma14.7.2
Product: macOSSonoma14.7.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-44225: tvOS18.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: tvOS18.2
Apple Security Update: About the security content of tvOS18.2
Product: tvOS18.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-54514: macOSSonoma14.7.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: macOSSonoma14.7.2
Apple Security Update: About the security content of macOSSonoma14.7.2
Product: macOSSonoma14.7.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-44225: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: macOSVentura13.7.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: macOSVentura13.7.2
Apple Security Update: About the security content of macOSVentura13.7.2
Product: macOSVentura13.7.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-45490: tvOS18.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: tvOS18.2
Apple Security Update: About the security content of tvOS18.2
Product: tvOS18.2
CVE: CVE-2024-45490
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-44225: watchOS11.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: watchOS11.2
Apple Security Update: About the security content of watchOS11.2
Product: watchOS11.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-54514: watchOS11.2
vendor_apple·2024-12-11·CVSS 7.5
CVE-2024-54514 [HIGH] CVE-2024-54514: watchOS11.2
Apple Security Update: About the security content of watchOS11.2
Product: watchOS11.2
CVE: CVE-2024-54514
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
Apple
CVE-2024-44225: iOS18.2 and iPadOS18.2
vendor_apple·2024-12-11·CVSS 7.8
CVE-2024-44225 [HIGH] CVE-2024-44225: iOS18.2 and iPadOS18.2
Apple Security Update: About the security content of iOS18.2 and iPadOS18.2
Product: iOS18.2 and iPadOS18.2
CVE: CVE-2024-44225
Component: CVE-2024-45490
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
CISA ICS
Subnet Solutions PowerSYSTEM Center
cisa_ics·2024-11-12·CVSS 7.5
[HIGH] Subnet Solutions PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions PowerSYSTEM Center
Release DateNovember 12, 2024
Alert CodeICSA-24-317-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Subnet Solutions
- Equipment: PowerSYSTEM Center
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Integer Overflow or Wraparound
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to cause an integer overflow on the affected device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SUBNET PowerSYSTEM Center, an OT device management platform, are affected:
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2024-09-17·CVSS 7.5
CVE-2024-45491 [HIGH] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
USN-7001-1 fixed vulnerabilities in xmltol library. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input
length was provided. An attacker could use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45491
BSD
OpenBSD 7.5 Errata 007: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.5 Errata 007: SECURITY FIX
OpenBSD 7.5 Errata 007: SECURITY FIX
007: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-17·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary
BSD
OpenBSD 7.4 Errata 020: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.4 Errata 020: SECURITY FIX
OpenBSD 7.4 Errata 020: SECURITY FIX
020: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2024-09-12·CVSS 7.5
CVE-2024-45491 [HIGH] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input length
was provided. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2024-45491)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-12·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libexpat: Negative Length Parsing Vulnerability in libexpat
vendor_redhat·2024-08-30·CVSS 7.5
CVE-2024-45490 [HIGH] CWE-190 libexpat: Negative Length Parsing Vulnerability in libexpat
libexpat: Negative Length Parsing Vulnerability in libexpat
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
A flaw was found in libexpat's xmlparse.c component. This vulnerability allows an attacker to cause improper handling of XML data by providing a negative length value to the XML_ParseBuffer function.
Statement: The CVE-2024-45490 vulnerability is rated as moderate severity because while it allows for memory corruption through improper argument handling in XML_ParseBuffer, the exploitability is limited. Specifically, it requires an unlikely scenario where the input passed to the function has a negative length (len < 0), which would typically not occur in well-formed applications. Moreover, while the impact includes
Microsoft
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
vendor_msrc·2024-08-13·CVSS 7.5
CVE-2024-45490 [HIGH] CWE-611 An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2024-45490: expat - An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a n...
vendor_debian·2024·CVSS 7.5
CVE-2024-45490 [HIGH] CVE-2024-45490: expat - An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a n...
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Scope: local
bookworm: resolved (fixed in 2.5.0-1+deb12u1)
bullseye: resolved (fixed in 2.2.10-2+deb11u6)
forky: resolved (fixed in 2.6.2-2)
sid: resolved (fixed in 2.6.2-2)
trixie: resolved (fixed in 2.6.2-2)
No detection rules found.
No public exploits indexed.
https://github.com/libexpat/libexpat/issues/887https://github.com/libexpat/libexpat/pull/890http://seclists.org/fulldisclosure/2024/Dec/10http://seclists.org/fulldisclosure/2024/Dec/12http://seclists.org/fulldisclosure/2024/Dec/6http://seclists.org/fulldisclosure/2024/Dec/7http://seclists.org/fulldisclosure/2024/Dec/8https://lists.debian.org/debian-lts-announce/2024/09/msg00036.htmlhttps://security.netapp.com/advisory/ntap-20241018-0004/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-613116.html
2024-08-30
Published