[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256488

 
 

909

 
 

199193

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2022-1654 --- expat

ID: oval:org.secpod.oval:def:1601601Date: (C)2022-12-13   (M)2024-01-23
Class: PATCHFamily: unix




A vulnerability was found in expat. With this flaw, it is possible to create a situation in which parsing is suspended while substituting in an internal entity so that XML_ResumeParser directly uses the internalEntityProcessor as its processor. If the subsequent parse includes some unclosed tags, this will return without calling storeRawNames to ensure that the raw versions of the tag names are stored in memory other than the parse buffer itself. Issues occur if the parse buffer is changed or reallocated , problems occur. Using this vulnerability in the doContent function allows an attacker to triage a denial of service or potentially arbitrary code execution

Platform:
Amazon Linux AMI
Product:
expat
Reference:
ALAS-2022-1654
CVE-2022-40674
CVE    1
CVE-2022-40674

© SecPod Technologies