Описание
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
Отчет
This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | expat | Will not fix | ||
Red Hat Enterprise Linux 5 | firefox | Not affected | ||
Red Hat Enterprise Linux 5 | thunderbird | Not affected | ||
Red Hat Enterprise Linux 6 | compat-expat1 | Will not fix | ||
Red Hat Enterprise Linux 6 | expat | Will not fix | ||
Red Hat Enterprise Linux 6 | firefox | Not affected | ||
Red Hat Enterprise Linux 6 | thunderbird | Not affected | ||
Red Hat Enterprise Linux 7 | expat | Will not fix | ||
Red Hat Enterprise Linux 7 | firefox | Not affected | ||
Red Hat Enterprise Linux 7 | python | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1396540firefox: Possible integer overflow to fix inside XML_Parse in Expat
9.8 Critical
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 7 лет назад
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVSS3: 9.8
nvd
около 7 лет назад
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVSS3: 9.8
debian
около 7 лет назад
An integer overflow during the parsing of XML using the Expat library. ...
CVSS3: 9.8
github
около 3 лет назад
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
9.8 Critical
CVSS3
4.3 Medium
CVSS2