[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253741

 
 

909

 
 

197391

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

expat: Heap overflow in XML_GetCurrentLineNumber (CVE-2019-15903)

ID: oval:org.secpod.oval:def:59761Date: (C)2019-11-20   (M)2024-05-22
Class: PATCHFamily: unix




In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber then resulted in a heap-based buffer over-read.

Platform:
Alpine Linux 3.10
Alpine Linux 3.8
Alpine Linux 3.9
Alpine Linux 3.7
Product:
expat
Reference:
10791
CVE-2019-15903
CVE    1
CVE-2019-15903

© SecPod Technologies