REDHAT-BUG-2262877: Medium severity libexpat libexpat vulnerability
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
References: [1] https://github.com/libexpat/libexpat/pull/789 [2] https://github.com/libexpat/libexpat/commit/34b598c5f594b015c513c73f06e7ced3323edbf1
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2262877?
The severity of REDHAT-BUG-2262877 is categorized as a denial of service due to resource consumption issues.
How do I fix REDHAT-BUG-2262877?
To fix REDHAT-BUG-2262877, upgrade libexpat to a version higher than 2.5.0.
What software is affected by REDHAT-BUG-2262877?
REDHAT-BUG-2262877 affects the libexpat library versions up to and including 2.5.0.
What is the exploit type of REDHAT-BUG-2262877?
The exploit type of REDHAT-BUG-2262877 is a denial of service caused by excessive reparsings with large tokens.
How is REDHAT-BUG-2262877 triggered?
REDHAT-BUG-2262877 is triggered by providing large tokens that require multiple buffer fills during parsing.