Описание
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
expat | fixed | 2.4.8-2 | package | |
libxmltok | removed | package | ||
libxmltok | ignored | bookworm | package |
Примечания
https://github.com/libexpat/libexpat/pull/629
https://github.com/libexpat/libexpat/pull/640
https://github.com/libexpat/libexpat/commit/4a32da87e931ba54393d465bb77c40b5c33d343b
EPSS
Процентиль: 69%
0.00625
Низкий
Связанные уязвимости
CVSS3: 8.1
ubuntu
почти 3 года назад
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVSS3: 8.1
redhat
почти 3 года назад
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVSS3: 8.1
nvd
почти 3 года назад
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
EPSS
Процентиль: 69%
0.00625
Низкий