CVE-2024-50602: Medium severity NetApp Active Iq Unified Manager Vmware Vsphere vulnerability
An issue was discovered in libexpat before 2.6.4. There is a crash within the XMLResumeParser function because XMLStopParser can stop/suspend an unstarted parser.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.6.4-1 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50602?
CVE-2024-50602 has a medium severity rating due to the potential for causing crashes during XML parsing.
How do I fix CVE-2024-50602?
To fix CVE-2024-50602, upgrade libexpat to version 2.6.4 or higher.
What software versions are affected by CVE-2024-50602?
CVE-2024-50602 affects versions of libexpat prior to 2.6.4, including 2.2.10-2+deb11u5, 2.2.10-2+deb11u6, and 2.5.0-1+deb12u1.
What kind of exploit is associated with CVE-2024-50602?
CVE-2024-50602 can be exploited to crash the application using libexpat when the XML_ResumeParser function is invoked improperly.
Is CVE-2024-50602 publicly disclosed?
Yes, CVE-2024-50602 has been publicly disclosed and is documented for security awareness.