Описание
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
A memory leak flaw was found in Expat. If an XML file processed by an application linked against Expat triggered a memory re-allocation failure, Expat failed to free the previously allocated memory. This could cause the application to exit unexpectedly or crash when all available memory is exhausted.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Certificate System 7.3 | expat | Will not fix | ||
Red Hat Directory Server 8 | expat | Affected | ||
Red Hat Enterprise Linux 4 | expat | Will not fix | ||
Red Hat Enterprise Linux 5 | xmlrpc-c | Will not fix | ||
Red Hat Enterprise Linux 6 | compat-expat1 | Will not fix | ||
Red Hat Enterprise Linux 6 | mingw32-expat | Will not fix | ||
Red Hat JBoss Core Services | expat | Affected | ||
Red Hat JBoss Enterprise Application Platform 6 | expat | Affected | ||
Red Hat JBoss Enterprise Web Server 2 | expat | Affected | ||
Red Hat JBoss Enterprise Web Server 3 | expat | Fix deferred |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
5 Medium
CVSS2
Связанные уязвимости
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat ...
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
7.5 High
CVSS3
5 Medium
CVSS2