ALAS-2020-1460 --- expatDeprecated |
ID: oval:org.secpod.oval:def:1601378 | Date: (C)2020-12-21 (M)2024-06-14 |
Class: PATCH | Family: unix |
It was discovered that the "setElementTypePrefix" function incorrectly extracted XML namespace prefixes. By tricking an application into processing a specially crafted XML file, an attacker could cause unusually high consumption of memory resources and possibly lead to a denial of service. In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber then resulted in a heap-based buffer over-read
Platform: |
Amazon Linux AMI |