Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45960

Опубликовано: 01 янв. 2022
Источник: debian
EPSS Низкий

Описание

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
expatfixed2.4.3-1package
libxmltokremovedpackage
libxmltokignoredbookwormpackage

Примечания

  • https://github.com/libexpat/libexpat/issues/531

  • https://github.com/libexpat/libexpat/pull/534

  • Fixed by: https://github.com/libexpat/libexpat/commit/0adcb34c49bee5b19bd29b16a578c510c23597ea (R_2_4_3)

EPSS

Процентиль: 54%
0.00309
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
redhat
почти 4 года назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
nvd
около 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 8.8
github
почти 4 года назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

EPSS

Процентиль: 54%
0.00309
Низкий