First published: Sun Mar 10 2024(Updated: )
libexpat could allow a remote attacker to obtain sensitive information, caused by improper handling of XML external entity (XXE) declarations by the XML_ExternalEntityParserCreate function. By using a specially crafted XML content, a remote attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.6-2+deb10u4<=2.2.6-2+deb10u7<=2.2.10-2+deb11u5<=2.5.0-1<=2.5.0-2 | 2.6.2-1 |
ubuntu/expat | <2.4.7-1ubuntu0.3 | 2.4.7-1ubuntu0.3 |
ubuntu/expat | <2.5.0-2ubuntu0.1 | 2.5.0-2ubuntu0.1 |
redhat/expat | <2.6.2 | 2.6.2 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.