Описание
libexpat before 2.8.2 has an integer overflow in addBinding.
A flaw was found in libexpat. This vulnerability, an integer overflow in the addBinding function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity.
Отчет
This Moderate impact flaw in libexpat, an XML parsing library, could lead to arbitrary code execution through an integer overflow in the addBinding function. Exploitation requires local access and high attack complexity, which limits its immediate risk in standard Red Hat deployments. The vulnerability primarily affects applications that process untrusted XML data.
Меры по смягчению последствий
Do not process untrusted or unvalidated XML with libexpat-based applications. Enforce strict maximum size limits on XML input and namespace URI lengths before parsing
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | ||
| Red Hat Enterprise Linux 6 | compat-expat1 | Out of support scope | ||
| Red Hat Enterprise Linux 6 | expat | Out of support scope | ||
| Red Hat Enterprise Linux 7 | expat | Out of support scope | ||
| Red Hat Enterprise Linux 7 | firefox | Out of support scope | ||
| Red Hat Enterprise Linux 8 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 8 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mingw-expat | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.9 Medium
CVSS3
Связанные уязвимости
libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in addBinding.
EPSS
6.9 Medium
CVSS3