Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45960

Опубликовано: 01 янв. 2022
Источник: debian

Описание

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
expatfixed2.4.3-1package
libxmltokremovedpackage
libxmltokignoredbookwormpackage

Примечания

  • https://github.com/libexpat/libexpat/issues/531

  • https://github.com/libexpat/libexpat/pull/534

  • Fixed by: https://github.com/libexpat/libexpat/commit/0adcb34c49bee5b19bd29b16a578c510c23597ea (R_2_4_3)

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
redhat
больше 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
nvd
больше 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVSS3: 8.8
msrc
больше 4 лет назад

In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory).

CVSS3: 8.8
github
больше 4 лет назад

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).