Description


libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Related CPE's



o

debian

debian_linux

2

o

fedoraproject

fedora

3

References


https://github.com/libexpat/libexpat/pull/629

Issue TrackingPatchThird Party Advisory

https://github.com/libexpat/libexpat/pull/640

Issue TrackingPatchThird Party Advisory











https://github.com/libexpat/libexpat/pull/629

Issue TrackingPatchThird Party Advisory

https://github.com/libexpat/libexpat/pull/640

Issue TrackingPatchThird Party Advisory










Weaknesses



CWE-416

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-416

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-09-14T09:15:54.020Z

3 years ago

Last modified

2025-05-30T18:15:30.970Z

7 months ago