CVE-2021-46143: Integer Overflow
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Other sources
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for mgroupSize.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-46143.
What is the severity level of CVE-2021-46143?
The severity level of CVE-2021-46143 is high with a CVSS score of 7.8.
What is the impact of CVE-2021-46143?
The highest threat from CVE-2021-46143 is to availability and confidentiality.
Which software versions are affected by CVE-2021-46143?
The affected software versions include Expat (libexpat) before 2.4.3.
How can I fix CVE-2021-46143?
To fix CVE-2021-46143, update Expat to version 2.4.3.