Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15903

Опубликовано: 04 сент. 2019
Источник: redhat
CVSS3: 7.5

Описание

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5expatOut of support scope
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 5xmlrpc-cOut of support scope
Red Hat Enterprise Linux 5xulrunnerNot affected
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6xulrunnerNot affected
Red Hat Enterprise Linux 7pythonNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1752592expat: heap-based buffer over-read via crafted XML input

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

CVSS3: 7.5
nvd
почти 6 лет назад

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

CVSS3: 7.5
debian
почти 6 лет назад

In libexpat before 2.2.8, crafted XML input could fool the parser into ...

suse-cvrf
больше 5 лет назад

Security update for expat

suse-cvrf
больше 5 лет назад

Security update for expat

7.5 High

CVSS3