Описание
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data.
Отчет
This Moderate severity flaw in libexpat, an XML parsing library, is due to an integer overflow during the processing of entity declarations. While exploitation could lead to arbitrary code execution or information disclosure, the attack requires local access and has high complexity, limiting its immediate impact on typical Red Hat deployments.
Меры по смягчению последствий
To prevent exploitation explicitly disable all internal and external XML entity processing within your application's parser configuration. Additionally, use a Web Application Firewall (WAF) to strictly limit the maximum size of incoming XML payloads to prevent the overflow trigger.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | ||
| Red Hat Enterprise Linux 6 | compat-expat1 | Out of support scope | ||
| Red Hat Enterprise Linux 6 | expat | Out of support scope | ||
| Red Hat Enterprise Linux 7 | expat | Out of support scope | ||
| Red Hat Enterprise Linux 7 | firefox | Out of support scope | ||
| Red Hat Enterprise Linux 8 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 8 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mingw-expat | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.9 Medium
CVSS3
Связанные уязвимости
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
EPSS
6.9 Medium
CVSS3