Описание
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| expat | fixed | 2.8.2-1 | package |
Примечания
https://github.com/libexpat/libexpat/pull/1262
Fixed by: https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13
EPSS
Процентиль: 3%
0.00124
Низкий
Связанные уязвимости
CVSS3: 6.9
ubuntu
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVSS3: 6.9
nvd
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVSS3: 6.9
msrc
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVSS3: 6.9
github
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
EPSS
Процентиль: 3%
0.00124
Низкий