Описание
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
An integer overflow flaw was found in expat. This issue affects the encoding name parameter at the parser creation time, which is often hard-coded (rather than user input), takes a value in the gigabytes to trigger, and on a 64-bit machine. This flaw can cause a denial of service.
Отчет
This flaw has been rated as having a severity of Moderate. The encoding name parameter is often hard-coded (rather than user input) and it would take a value in the gigabytes for the name to trigger this issue. The versions of expat
as shipped with Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they did not include the vulnerable copyString() function.
Меры по смягчению последствий
There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | expat | Not affected | ||
Red Hat Enterprise Linux 7 | expat | Not affected | ||
Red Hat Enterprise Linux 7 | firefox | Out of support scope | ||
Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | ||
Red Hat Enterprise Linux 8 | firefox | Not affected | ||
Red Hat Enterprise Linux 8 | firefox:flatpak/firefox | Not affected | ||
Red Hat Enterprise Linux 8 | thunderbird | Not affected | ||
Red Hat Enterprise Linux 8 | thunderbird:flatpak/thunderbird | Not affected | ||
Red Hat Enterprise Linux 8 | xmlrpc-c | Not affected | ||
Red Hat Enterprise Linux 9 | firefox | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in ...
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
EPSS
7.5 High
CVSS3