Описание
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| expat | fixed | 2.8.0-1 | package | |
| expat | no-dsa | bookworm | package | |
| expat | postponed | bullseye | package |
Примечания
https://github.com/libexpat/libexpat/issues/47
https://github.com/libexpat/libexpat/pull/1183
EPSS
Процентиль: 33%
0.00398
Низкий
Связанные уязвимости
CVSS3: 2.9
ubuntu
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS3: 3.7
redhat
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS3: 2.9
nvd
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS3: 2.9
github
4 месяца назад
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
EPSS
Процентиль: 33%
0.00398
Низкий