CVE-2024-45491
published 2024-08-30CVE-2024-45491: An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.13%
62.8th percentile
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| libexpat_project | libexpat | < 2.6.3 | 2.6.3 |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
expat vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
libxmltok vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] libxmltok vulnerabilities
libxmltok vulnerabilities
USN-7001-1 fixed vulnerabilities in xmltol library. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input
length was provided. An attacker could use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45491)
OSV
expat vulnerabilities
osv·2024-09-12·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
libxmltok vulnerabilities
osv·2024-09-12·CVSS 7.5
CVE-2024-45490 [HIGH] libxmltok vulnerabilities
libxmltok vulnerabilities
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input length
was provided. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2024-45491)
OSV
CVE-2024-45491: An issue was discovered in libexpat before 2
osv·2024-08-30·CVSS 9.8
CVE-2024-45491 [CRITICAL] CVE-2024-45491: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
GHSA
GHSA-784x-7qm2-gp97: An issue was discovered in libexpat before 2
ghsa_unreviewed·2024-08-30
CVE-2024-45491 [HIGH] CWE-190 GHSA-784x-7qm2-gp97: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: NULL Pointer Dereference, Improper Validation of Integrity Check Value, Improper Restriction of XML External Entity Reference, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a Denial-of-Servi
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
CISA ICS
Subnet Solutions PowerSYSTEM Center
cisa_ics·2024-11-12·CVSS 7.5
[HIGH] Subnet Solutions PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions PowerSYSTEM Center
Release DateNovember 12, 2024
Alert CodeICSA-24-317-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Subnet Solutions
- Equipment: PowerSYSTEM Center
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Integer Overflow or Wraparound
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to cause an integer overflow on the affected device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SUBNET PowerSYSTEM Center, an OT device management platform, are affected:
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2024-09-17·CVSS 7.5
CVE-2024-45491 [HIGH] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
USN-7001-1 fixed vulnerabilities in xmltol library. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input
length was provided. An attacker could use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45491
BSD
OpenBSD 7.5 Errata 007: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.5 Errata 007: SECURITY FIX
OpenBSD 7.5 Errata 007: SECURITY FIX
007: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-17·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary
BSD
OpenBSD 7.4 Errata 020: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.4 Errata 020: SECURITY FIX
OpenBSD 7.4 Errata 020: SECURITY FIX
020: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2024-09-12·CVSS 7.5
CVE-2024-45491 [HIGH] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input length
was provided. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2024-45491)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-12·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libexpat: Integer Overflow or Wraparound
vendor_redhat·2024-08-30·CVSS 9.8
CVE-2024-45491 [CRITICAL] libexpat: Integer Overflow or Wraparound
libexpat: Integer Overflow or Wraparound
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
An issue was found in libexpat’s internal dtdCopy function in xmlparse.c, It can have an integer overflow for nDefaultAtts on 32-bit platforms where UINT_MAX equals SIZE_MAX.
Statement: This vulnerability is classified as Moderate severity rather than Important due to its reliance on specific conditions for exploitation. The integer overflow in dtdCopy affecting nDefaultAtts is limited to 32-bit platforms, reducing the attack surface as many modern systems operate on 64-bit architectures. Additionally, while the impact can lead to denial of service and potentially arbitrary cod
Microsoft
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
vendor_msrc·2024-08-13·CVSS 9.8
CVE-2024-45491 [CRITICAL] CWE-190 An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marine
Debian
CVE-2024-45491: expat - An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have...
vendor_debian·2024·CVSS 9.8
CVE-2024-45491 [CRITICAL] CVE-2024-45491: expat - An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have...
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Scope: local
bookworm: resolved (fixed in 2.5.0-1+deb12u1)
bullseye: resolved (fixed in 2.2.10-2+deb11u6)
forky: resolved (fixed in 2.6.2-2)
sid: resolved (fixed in 2.6.2-2)
trixie: resolved (fixed in 2.6.2-2)
No detection rules found.
No public exploits indexed.
https://github.com/libexpat/libexpat/issues/888https://github.com/libexpat/libexpat/pull/891https://lists.debian.org/debian-lts-announce/2024/09/msg00036.htmlhttps://security.netapp.com/advisory/ntap-20241018-0003/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-613116.html
2024-08-30
Published