Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8176

Опубликовано: 14 мар. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-infra-legacy/trusty

not-affected

uses system expat
esm-infra/bionic

not-affected

uses system expat
esm-infra/focal

not-affected

uses system expat
esm-infra/xenial

not-affected

uses system expat
focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat
oracular

not-affected

uses system expat
plucky

not-affected

uses system expat

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-infra-legacy/trusty

not-affected

uses system expat
esm-infra/bionic

not-affected

uses system expat
esm-infra/focal

not-affected

uses system expat
esm-infra/xenial

not-affected

uses system expat
focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat
oracular

not-affected

uses system expat
plucky

not-affected

uses system expat

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-infra/bionic

not-affected

uses system expat
esm-infra/focal

not-affected

uses system expat
esm-infra/xenial

not-affected

uses system expat
focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat
oracular

not-affected

uses system expat
plucky

not-affected

uses system expat
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

uses system expat
esm-apps/jammy

not-affected

uses system expat
esm-apps/noble

not-affected

uses system expat
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat

Показывать по

РелизСтатусПримечание
devel

released

2.7.1-1
esm-infra-legacy/trusty

ignored

changes too intrusive
esm-infra/bionic

ignored

changes too intrusive
esm-infra/focal

ignored

changes too intrusive
esm-infra/xenial

ignored

changes too intrusive
focal

ignored

end of standard support, was ignored [changes too intrusive]
jammy

released

2.4.7-1ubuntu0.6
noble

released

2.6.1-2ubuntu0.3
oracular

released

2.6.2-2ubuntu0.2
plucky

released

2.7.1-1

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

uses system expat
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

uses system expat
esm-apps/jammy

not-affected

uses system expat
esm-apps/noble

not-affected

uses system expat
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

not-affected

uses system expat
focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system expat
esm-infra/bionic

not-affected

uses system expat
esm-infra/focal

not-affected

uses system expat
esm-infra/xenial

not-affected

uses system expat
focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

uses system expat
oracular

not-affected

uses system expat
plucky

not-affected

uses system expat
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

ignored

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

ignored

esm-apps/xenial

needs-triage

focal

ignored

jammy

ignored

noble

ignored

oracular

ignored

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code-not-compiled
esm-infra/bionic

not-affected

code-not-compiled
esm-infra/focal

not-affected

code-not-compiled
esm-infra/xenial

not-affected

code-not-compiled
focal

not-affected

code-not-compiled
jammy

not-affected

code-not-compiled
noble

not-affected

code-not-compiled
oracular

not-affected

code-not-compiled
plucky

not-affected

code-not-compiled
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

uses system expat
jammy

not-affected

uses system expat
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

CVSS3: 7.5
nvd
3 месяца назад

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
3 месяца назад

A stack overflow vulnerability exists in the libexpat library due to t ...

suse-cvrf
2 месяца назад

Security update for expat

7.5 High

CVSS3

Уязвимость CVE-2024-8176