Описание
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Ссылки
- Release Notes
- Issue Tracking
- Issue TrackingPatch
- Mailing List
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.0 (исключая)
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00398
Низкий
2.9 Low
CVSS3
7.5 High
CVSS3
Дефекты
CWE-331
Связанные уязвимости
CVSS3: 2.9
ubuntu
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS3: 3.7
redhat
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS3: 2.9
debian
4 месяца назад
libexpat before 2.8.0 uses insufficient entropy, and thus hash floodin ...
CVSS3: 2.9
github
4 месяца назад
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
EPSS
Процентиль: 33%
0.00398
Низкий
2.9 Low
CVSS3
7.5 High
CVSS3
Дефекты
CWE-331