Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-52426

Опубликовано: 04 фев. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

A flaw was found in Expat (libexpat). If XML_DTD is undefined at compile time, a recursive XML Entity Expansion condition can be triggered. This issue may lead to a condition where data is expanded exponentially, which will quickly consume system resources and cause a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 7thunderbirdOut of support scope
Red Hat Enterprise Linux 8expatNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8firefox:flatpak/firefoxWill not fix
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 8thunderbird:flatpak/thunderbirdWill not fix
Red Hat Enterprise Linux 8xmlrpc-cWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2262879expat: recursive XML entity expansion vulnerability

EPSS

Процентиль: 3%
0.00019
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

CVSS3: 5.5
nvd
больше 1 года назад

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

CVSS3: 5.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.5
debian
больше 1 года назад

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DT ...

CVSS3: 5.1
redos
около 1 года назад

Уязвимость expat

EPSS

Процентиль: 3%
0.00019
Низкий

5.5 Medium

CVSS3