First published: Fri Aug 30 2024(Updated: )
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.10-2+deb11u5 | 2.2.10-2+deb11u6 2.5.0-1+deb12u1 2.6.4-1 |
Debian (libexpat1) | <2.6.3 | |
IBM Rational Team Concert | <=1.0.0, 1.0.1, 1.0.2, 1.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45491 is classified as a high severity vulnerability due to the potential for integer overflow on 32-bit platforms.
To fix CVE-2024-45491, upgrade to libexpat version 2.6.3 or later.
Versions of libexpat earlier than 2.6.3 are affected by CVE-2024-45491.
CVE-2024-45491 primarily affects 32-bit platforms.
CVE-2024-45491 impacts libexpat, IBM Concert Software, and Debian packages that use affected versions.