First published: Fri Aug 30 2024(Updated: )
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Affected Software | Affected Version | How to fix |
---|---|---|
Expat | <2.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2308615 is classified as a medium severity vulnerability.
To fix REDHAT-BUG-2308615, update libexpat to version 2.6.3 or later.
The software affected by REDHAT-BUG-2308615 is Expat libexpat versions prior to 2.6.3.
REDHAT-BUG-2308615 is a software vulnerability related to input validation in the XML parsing function.
Yes, REDHAT-BUG-2308615 can lead to security risks such as denial of service or potential code execution.