CVE-2024-45492
published 2024-08-30CVE-2024-45492: An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.39%
69.3th percentile
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1+deb12u1 (bookworm) | expat 2.5.0-1+deb12u1 (bookworm) |
| libexpat_project | libexpat | < 2.6.3 | 2.6.3 |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
expat vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
expat vulnerabilities
osv·2024-09-12·CVSS 7.5
CVE-2024-45490 [HIGH] expat vulnerabilities
expat vulnerabilities
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
OSV
CVE-2024-45492: An issue was discovered in libexpat before 2
osv·2024-08-30·CVSS 9.8
CVE-2024-45492 [CRITICAL] CVE-2024-45492: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
GHSA
GHSA-5qxm-qvmj-8v79: An issue was discovered in libexpat before 2
ghsa_unreviewed·2024-08-30
CVE-2024-45492 [HIGH] CWE-190 GHSA-5qxm-qvmj-8v79: An issue was discovered in libexpat before 2
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: NULL Pointer Dereference, Improper Validation of Integrity Check Value, Improper Restriction of XML External Entity Reference, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a Denial-of-Servi
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (LibExpat) — CVE-2024-45492
vendor_oracle·2025-01-15·CVSS 9.8
CVE-2024-45492 [CRITICAL] Oracle Oracle Communications Risk Matrix: Install/Upgrade (LibExpat) — CVE-2024-45492
Oracle Oracle Communications Risk Matrix: Install/Upgrade (LibExpat) vulnerability
CVE: CVE-2024-45492
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
CISA ICS
Subnet Solutions PowerSYSTEM Center
cisa_ics·2024-11-12·CVSS 7.5
[HIGH] Subnet Solutions PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions PowerSYSTEM Center
Release DateNovember 12, 2024
Alert CodeICSA-24-317-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Subnet Solutions
- Equipment: PowerSYSTEM Center
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Integer Overflow or Wraparound
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to cause an integer overflow on the affected device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SUBNET PowerSYSTEM Center, an OT device management platform, are affected:
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) — CVE-2024-45492
vendor_oracle·2024-10-15·CVSS 9.8
CVE-2024-45492 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) — CVE-2024-45492
Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) vulnerability
CVE: CVE-2024-45492
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
BSD
OpenBSD 7.5 Errata 007: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.5 Errata 007: SECURITY FIX
OpenBSD 7.5 Errata 007: SECURITY FIX
007: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-17·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
USN-7000-1 fixed vulnerabilities in Expat. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary
BSD
OpenBSD 7.4 Errata 020: SECURITY FIX
bsd_advisories·2024-09-17·CVSS 7.5
CVE-2024-45490 [HIGH] OpenBSD 7.4 Errata 020: SECURITY FIX
OpenBSD 7.4 Errata 020: SECURITY FIX
020: SECURITY FIX: September 17, 2024
All architectures In libexpat add integer range checks. CVE-2024-45490 CVE-2024-45491 CVE-2024-45492
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-09-12·CVSS 7.5
CVE-2024-45492 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
Shang-Hung Wan discovered that Expat did not properly handle certain
function calls when a negative input length was provided. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat did not properly handle the
potential for an integer overflow on 32-bit platforms. An attacker
could use this issue to cause a denial of service or possibly execute
arbitrary code. (CVE-2024-45491, CVE-2024-45492)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libexpat: integer overflow
vendor_redhat·2024-08-30·CVSS 9.8
CVE-2024-45492 [CRITICAL] libexpat: integer overflow
libexpat: integer overflow
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
A flaw was found in libexpat's internal nextScaffoldPart function in xmlparse.c. It can have an integer overflow for m_groupSize on 32-bit platforms where UINT_MAX equals SIZE_MAX.
Statement: CVE-2024-45492 is categorized as a Moderate severity issue rather than Important due to the specific conditions required for exploitation and the limited scope of impact. While an integer overflow in the nextScaffoldPart function on 32-bit platforms can potentially lead to denial of service (DoS) or, in rare cases, arbitrary code execution, the vulnerability is platform-specific, affecting only
Microsoft
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
vendor_msrc·2024-08-13·CVSS 9.8
CVE-2024-45492 [CRITICAL] CWE-190 An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Debian
CVE-2024-45492: expat - An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c...
vendor_debian·2024·CVSS 9.8
CVE-2024-45492 [CRITICAL] CVE-2024-45492: expat - An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c...
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Scope: local
bookworm: resolved (fixed in 2.5.0-1+deb12u1)
bullseye: resolved (fixed in 2.2.10-2+deb11u6)
forky: resolved (fixed in 2.6.2-2)
sid: resolved (fixed in 2.6.2-2)
trixie: resolved (fixed in 2.6.2-2)
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications followed,
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications fol
Qualys
Oracle Critical Patch Update, October 2024 Security Update Review
blogs_qualys·2024-10-16
Oracle Critical Patch Update, October 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle released the last quarterly edition of this year’s Critical Patch Update. The update contains patches for 334 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 100 constituting about 30% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 45 and 32 security patches, respectively.
244
Qualys
Oracle Critical Patch Security Update: October 2024 | Qualys
blogs_qualys·2024-10-16
Oracle Critical Patch Security Update: October 2024 | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle released the last quarterly edition of this year’s Critical Patch Update. The update contains patches for 334 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 100 constituting about 30% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 45 and 32 security patches, respectively.
Bugzilla
CVE-2024-45492 libexpat: integer overflow
bugzilla·2024-08-30·CVSS 9.8
CVE-2024-45492 [CRITICAL] CVE-2024-45492 libexpat: integer overflow
CVE-2024-45492 libexpat: integer overflow
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:6754 https://access.redhat.com/errata/RHSA-2024:6754
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:6989 https://access.redhat.com/errata/RHSA-2024:6989
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.16
Via RHSA-2024:7599 https://access.redhat.com/errata/RHSA-2024:7599
---
This issue has been addressed in the following products:
Red Hat OpenS
https://github.com/libexpat/libexpat/issues/889https://github.com/libexpat/libexpat/pull/892https://lists.debian.org/debian-lts-announce/2024/09/msg00036.htmlhttps://security.netapp.com/advisory/ntap-20241018-0005/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-613116.html
2024-08-30
Published