Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28757

Опубликовано: 10 мар. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

An XML Entity Expansion flaw was found in libexpat. This flaw allows an attacker to cause a denial of service when there is an isolated use of external parsers.

Отчет

Direct recursion of parameter entities repeatedly referenced themselves, creating a loop that was not detected in the external subset. This is against XML rules and caused unpredictable behaviour during runtime, which could lead to a denial of service (DoS) attack

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-expat1Not affected
Red Hat Enterprise Linux 6expatNot affected
Red Hat Enterprise Linux 7expatNot affected
Red Hat Enterprise Linux 8expatNot affected
Red Hat Enterprise Linux 9expatFixedRHBA-2024:251830.04.2024
Red Hat Enterprise Linux 9expatFixedRHSA-2024:153026.03.2024
Red Hat Enterprise Linux 9expatFixedRHBA-2024:251830.04.2024
Red Hat Enterprise Linux 9expatFixedRHSA-2024:153026.03.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportexpatFixedRHSA-2024:392613.06.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776

EPSS

Процентиль: 64%
0.00474
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVSS3: 7.5
nvd
больше 1 года назад

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVSS3: 7.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
больше 1 года назад

libexpat through 2.6.1 allows an XML Entity Expansion attack when ther ...

CVSS3: 7.5
github
больше 1 года назад

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

EPSS

Процентиль: 64%
0.00474
Низкий

7.5 High

CVSS3