Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8w9-7fww-v592

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
больше 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

redhat
больше 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

nvd
больше 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

debian
больше 13 лет назад

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values ...

oracle-oval
больше 13 лет назад

ELSA-2012-0731: expat security update (MODERATE)

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-400