Описание
libexpat before 2.8.2 has an integer overflow in storeAtts.
A flaw was found in libexpat. An integer overflow vulnerability exists in the storeAtts function. This flaw could allow an attacker to corrupt memory, leading to a denial of service, information disclosure, or potentially arbitrary code execution, compromising the integrity and confidentiality of data.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-chatbot-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-chatbot-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | expat | Under investigation | ||
| Red Hat Enterprise Linux 6 | compat-expat1 | Under investigation | ||
| Red Hat Enterprise Linux 6 | expat | Under investigation | ||
| Red Hat Enterprise Linux 7 | expat | Under investigation | ||
| Red Hat Enterprise Linux 8 | expat | Under investigation | ||
| Red Hat Enterprise Linux 8 | mingw-expat | Under investigation | ||
| Red Hat Enterprise Linux 9 | expat | Under investigation |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2491186libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
EPSS
Процентиль: 1%
0.00102
Низкий
6.9 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.9
ubuntu
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in storeAtts.
CVSS3: 6.9
nvd
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in storeAtts.
CVSS3: 6.9
msrc
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in storeAtts.
CVSS3: 6.9
debian
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in storeAtts.
CVSS3: 6.9
github
около 1 месяца назад
libexpat before 2.8.2 has an integer overflow in storeAtts.
EPSS
Процентиль: 1%
0.00102
Низкий
6.9 Medium
CVSS3